CVE-2012-4933
published 2012-10-20CVE-2012-4933: The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username of Ivanhoe and a hard-coded password of…
PriorityP260high7.8CVSS 2.0
AVNACLAuNCCINAN
EXPLOIT
EPSS
44.01%
98.6th percentile
The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username of Ivanhoe and a hard-coded password of Scott for the (1) GetFile_Password and (2) GetConfigInfo_Password operations, which allows remote attackers to obtain sensitive information via a crafted rtrlet/rtr request for the HandleMaintenanceCalls function.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| novell | zenworks_asset_management | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect unauthenticated requests to the rtrlet/rtr endpoint targeting the HandleMaintenanceCalls function, particularly for GetFile_Password or GetConfigInfo_Password operations ↗
- →Alert on HTTP requests to the rtrlet component of Novell ZENworks Asset Management Web Console that include hardcoded credential usage (Ivanhoe/Scott) for GetConfig or GetFile maintenance tasks ↗
- →Monitor for unauthenticated retrieval of configuration parameters (including database credentials in clear text) via the rtrlet component ↗
- →Alert on unauthenticated remote file access attempts via the rtrlet component, particularly large file retrievals up to 100,000,000 KB ↗
- ·The hardcoded credentials (Ivanhoe/Scott) are baked into the application and cannot be changed by configuration — exploitation requires no prior authentication ↗
- ·Vulnerability is specific to Novell ZENworks Asset Management version 7.5 Web Console; the rtrlet web application is the affected component ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Metasploit
Novell ZENworks Asset Management 7.5 Configuration Access
metasploit
Novell ZENworks Asset Management 7.5 Configuration Access
Novell ZENworks Asset Management 7.5 Configuration Access
This module exploits a hardcoded user and password for the GetConfig maintenance task in Novell ZENworks Asset Management 7.5. The vulnerability exists in the Web Console and can be triggered by sending a specially crafted request to the rtrlet component, allowing a remote unauthenticated user to retrieve the configuration parameters of Novell Zenworks Asset Management, including the database credentials in clear text. This module has been successfully tested on Novell ZENworks Asset Management 7.5.
Metasploit
Novell ZENworks Asset Management 7.5 Remote File Access
metasploit
Novell ZENworks Asset Management 7.5 Remote File Access
Novell ZENworks Asset Management 7.5 Remote File Access
This module exploits a hardcoded user and password for the GetFile maintenance task in Novell ZENworks Asset Management 7.5. The vulnerability exists in the Web Console and can be triggered by sending a specially crafted request to the rtrlet component, allowing a remote unauthenticated user to retrieve a maximum of 100_000_000 KB of remote files. This module has been successfully tested on Novell ZENworks Asset Management 7.5.
No writeups or analysis indexed.
http://www.kb.cert.org/vuls/id/332412http://www.securitytracker.com/id?1027682https://community.rapid7.com/community/metasploit/blog/2012/10/15/cve-2012-4933-novell-zenworkshttps://exchange.xforce.ibmcloud.com/vulnerabilities/79252http://www.kb.cert.org/vuls/id/332412http://www.securitytracker.com/id?1027682https://community.rapid7.com/community/metasploit/blog/2012/10/15/cve-2012-4933-novell-zenworkshttps://exchange.xforce.ibmcloud.com/vulnerabilities/79252
2012-10-20
Published