CVE-2002-2170: High severity Working Resources Inc. BadBlue vulnerability
Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but does not provide additional authentication, which allows remote attackers to execute arbitrary code via a web page containing an HTTP POST request that accesses the dir.hts page on the localhost and adds an entire hard drive to be shared.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
On hosts running BadBlue, block remote HTTP POST (and other) requests to the /dir.hts resource from any non-localhost IPs. Implement this via host firewall rules or perimeter ACLs to allow access to /dir.hts only from 127.0.0.1.
- Compensating control
Restrict access to BadBlue's web-based administrative functions to the local host only (127.0.0.1) using network-level controls or host firewall rules; deny administrative HTTP access from all external IP addresses.
- Operational
Audit systems running BadBlue for unauthorized shares created by this vulnerability (for example, an entire hard drive being shared). Remove any unauthorized shares and restore intended share permissions and access controls.
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2170?
CVE-2002-2170 is classified as a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2002-2170?
To fix CVE-2002-2170, upgrade to a later version of BadBlue Enterprise Edition that includes additional authentication measures.
What types of attacks are possible due to CVE-2002-2170?
CVE-2002-2170 allows remote attackers to execute arbitrary code via specially crafted HTTP POST requests.
Which versions of BadBlue are affected by CVE-2002-2170?
CVE-2002-2170 affects BadBlue Enterprise Edition versions 1.7 to 1.74.
Is there a mitigation for CVE-2002-2170 without upgrading?
If upgrading is not immediately possible, implementing IP address restrictions and monitoring can provide some mitigation for CVE-2002-2170.