Remote Code Execution Vulnerability in Novell ZENworks Configuration Management
CVE-2013-1080

Currently unrated

Key Information:

Vendor

Novell

Vendor
CVE Published:
29 March 2013

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC๐ŸŸฃ EPSS 72%

What is CVE-2013-1080?

The web server component of Novell ZENworks Configuration Management versions prior to 11.2.4 is vulnerable to a remote code execution exploit due to improper authentication mechanisms for certain JSP pages. An attacker can exploit this vulnerability through crafted requests sent to TCP port 443, potentially allowing them to conduct directory traversal attacks. This can lead to unauthorized file uploads and execution of arbitrary programs, exposing the system to significant risks.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

EPSS Score

72% chance of being exploited in the next 30 days.

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.