OSI-1501
The XML parser of Cisco Prime Service Catalog suffers from a vulnerability that could allow an authenticated remote attacker to either cause denial of service conditions (resources consumption) or retrieve sensitive data (local data access).
Alexis Dimitriadis (a.dimitriadis[a t]obrela[do t]com)
CVE-2015-0581: Cisco Prime Service Catalog XML External Entity Processing Vulnerability
CVSS Base Score: 7.0, CVSS Temporal Score: 5.8
09/06/2014
Cisco has released Prime Service Catalog 10.1 as well as a patch for 9.4.1, 9.4.1R2, 10.0, and 10.0R2 to remediate this vulnerability.
Mitre entry: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0581
Cisco advisory: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150128-psc-xmlee
The following information represents a PoC aiming to access the ‘boot.ini’ local file of the host lying underneath; note that directories can also be listed.
/RequestCenter/services/ServiceManagerTaskService
Post data:
]>
username&varname; password
username 0
9999 1
2