CVE-2002-2170: High severity Working Resources Inc. BadBlue vulnerability

Published Dec 31, 2002
·
Updated

Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but does not provide additional authentication, which allows remote attackers to execute arbitrary code via a web page containing an HTTP POST request that accesses the dir.hts page on the localhost and adds an entire hard drive to be shared.

Affected Software

4 affected components
Working Resources Inc. BadBlue=enterprise_1.7
Working Resources Inc. BadBlue=enterprise_1.7.3
Working Resources Inc. BadBlue=enterprise_1.7.2
Working Resources Inc. BadBlue=enterprise_1.7.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    On hosts running BadBlue, block remote HTTP POST (and other) requests to the /dir.hts resource from any non-localhost IPs. Implement this via host firewall rules or perimeter ACLs to allow access to /dir.hts only from 127.0.0.1.

  2. Compensating control

    Restrict access to BadBlue's web-based administrative functions to the local host only (127.0.0.1) using network-level controls or host firewall rules; deny administrative HTTP access from all external IP addresses.

  3. Operational

    Audit systems running BadBlue for unauthorized shares created by this vulnerability (for example, an entire hard drive being shared). Remove any unauthorized shares and restore intended share permissions and access controls.

Event History

Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Nov 16, 2005
CVE Published
via MITRE·09:17 PM
Data Sourced
via MITRE·09:17 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2002-2170?

CVE-2002-2170 is classified as a high-severity vulnerability due to its potential for remote code execution.

2

How do I fix CVE-2002-2170?

To fix CVE-2002-2170, upgrade to a later version of BadBlue Enterprise Edition that includes additional authentication measures.

3

What types of attacks are possible due to CVE-2002-2170?

CVE-2002-2170 allows remote attackers to execute arbitrary code via specially crafted HTTP POST requests.

4

Which versions of BadBlue are affected by CVE-2002-2170?

CVE-2002-2170 affects BadBlue Enterprise Edition versions 1.7 to 1.74.

5

Is there a mitigation for CVE-2002-2170 without upgrading?

If upgrading is not immediately possible, implementing IP address restrictions and monitoring can provide some mitigation for CVE-2002-2170.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203