Vulnerability Description
ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Webnms Framework | 5.2 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/138244/WebNMS-Framework-5.2-SP1-Traversal-WExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2016/Aug/54ExploitMailing ListThird Party Advisory
- http://www.securityfocus.com/archive/1/539159/100/0/threaded
- http://www.securityfocus.com/bid/92402Third Party AdvisoryVDB Entry
- https://blogs.securiteam.com/index.php/archives/2712ExploitTechnical DescriptionThird Party Advisory
- https://forums.webnms.com/topic/recent-vulnerabilities-in-webnms-and-how-to-prot
- https://github.com/pedrib/PoC/blob/master/advisories/webnms-5.2-sp1-pwn.txtExploitThird Party Advisory
- https://www.exploit-db.com/exploits/40229/ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/138244/WebNMS-Framework-5.2-SP1-Traversal-WExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2016/Aug/54ExploitMailing ListThird Party Advisory
- http://www.securityfocus.com/archive/1/539159/100/0/threaded
- http://www.securityfocus.com/bid/92402Third Party AdvisoryVDB Entry
- https://blogs.securiteam.com/index.php/archives/2712ExploitTechnical DescriptionThird Party Advisory
- https://forums.webnms.com/topic/recent-vulnerabilities-in-webnms-and-how-to-prot
- https://github.com/pedrib/PoC/blob/master/advisories/webnms-5.2-sp1-pwn.txtExploitThird Party Advisory
FAQ
What is CVE-2016-6603?
CVE-2016-6603 is a vulnerability with a CVSS score of 9.8 (CRITICAL). ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.
How severe is CVE-2016-6603?
CVE-2016-6603 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-6603?
Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Webnms Framework.