APP: Novell ZENworks Configuration Management PreBoot Directory Traversal

This signature detects directory traversal attempts on Novell ZENworks Configuration Management. Successful attack attempts could allow an attacker to view sensitive system files.

Extended Description

Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a preboot update pathname, aka ZDI-CAN-1595.

Affected Products

Novell zenworks_configuration_management

References

BugTraq: 65912

CVE: CVE-2013-3706

Short Name
APP:NOVELL:ZENWORKS-DIR-TRAV
Severity
Major
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
CVE-2013-3706 Configuration Directory Management Novell PreBoot Traversal ZENworks bid:65912
Release Date
05/10/2014
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
Port
tcp/998
False Positive
Unknown
Vendors

Novell

CVSS Score

5.0

Found a potential security threat?