PHP file inclusion in ZoneMinder - CVE-2023-2603

 

PHP file inclusion in ZoneMinder - CVE-2023-2603

Published: March 1, 2023


Vulnerability identifier: #VU72703
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-2603
CWE-ID: CWE-98
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to include and execute arbitrary PHP files on the server.

The vulnerability exists due to incorrect input validation when including PHP files in web/ajax/modal.php. A remote non-authenticated attacker can send a specially crafted HTTP request to the affected application, include and execute arbitrary PHP code on the system with privileges of the web server.


Affected software

ZoneMinder
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
webMethods Managed File Transfer
ObjectScale
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
Platform Automation Toolkit
IBM supplied MQ Advanced container images
Dell PowerProtect Cyber Recovery
Robotic Process Automation for Cloud Pak
Service Interconnect
Isolation Segment
VMware Tanzu Application Service for VMs
Run Once Duration Override Operator for Red Hat OpenShift
Red Hat OpenShift Kernel Module Management
Service Telemetry Framework
OpenShift Pipelines
cert-manager Operator for Red Hat OpenShift
Migration Toolkit for Virtualization
Red Hat Advanced Cluster Management for Kubernetes
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat Advanced Cluster Security for Kubernetes
Red Hat Migration Toolkit for Applications
Red Hat OpenStack
IBM Cloud Pak for Business Automation
Oracle Communications Cloud Native Core Network Exposure Function
DevWorkspace Operator
Netcool Operations Insight
IBM MQ Operator
Custom Metrics Autoscaler Operator for Red Hat OpenShift
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
Juniper Cloud Native Router
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Ubuntu
Basesystem Module
openSUSE Leap
openEuler
Fedora
Node Health Check Operator
Self Node Remediation Operator
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Service Mesh
VMware Tanzu Operations Manager
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
Node Maintenance Operator
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
OpenShift API for Data Protection (OADP)
Network Observability plugin for the Openshift Console
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat OpenShift GitOps
AMQ Broker
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libcap2-bin (Ubuntu package)
libcap2 (Ubuntu package)
libcap-debugsource
libcap-devel
libcap-progs-debuginfo
libcap2-debuginfo
libcap2
libcap-progs
libcap2-debuginfo-64bit
libcap2-32bit
libcap2-debuginfo-32bit
pam_cap-32bit
libcap2-32bit-debuginfo
pam_cap
pam_cap-32bit-debuginfo
pam_cap-debuginfo
libcap
libcap-debuginfo
libcap-help
libcap (Red Hat package)
libpsx2-32bit-debuginfo
libpsx2-32bit
libpsx2-debuginfo
libpsx2
libcap-static
IBM Security Guardium
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
Dell EMC VxRail Appliance
Operational Decision Manager
Junos cRPD

How to mitigate CVE-2023-2603

Install updates from vendor's website.

ZoneMinder - update to 1.37.33
Isolation Segment - addressed in versions 2.11.36, 2.13.21, 3.0.14, 4.0.5
VMware Tanzu Application Service for VMs - addressed in versions 2.11.42, 2.13.24, 3.0.14, 4.0.5
Node Health Check Operator - update to 0.4.1
Self Node Remediation Operator - addressed in versions 0.5.1, 0.7.1
Red Hat OpenShift Serverless - update to 1.30.1
Run Once Duration Override Operator for Red Hat OpenShift - update to 1.0.1
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - addressed in versions 1.1.3, 1.2.0
OpenShift API for Data Protection (OADP) - update to 1.1.6
Red Hat OpenShift Kernel Module Management - update to 1.1.2
Service Telemetry Framework - update to 1.5.4
Migration Toolkit for Containers - addressed in versions 1.7.13, 1.8.0
OpenShift Pipelines - addressed in versions 1.10.6, 1.11.2
cert-manager Operator for Red Hat OpenShift - update to 1.11.5
Multicluster Engine for Kubernetes - addressed in versions 2.1.8, 2.2.7, 2.5.8
OpenShift Service Mesh - addressed in versions 2.2.10, 2.4.3, 2.4.8, 2.5.2
Migration Toolkit for Virtualization - update to 2.4.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.7, 2.7.7, 2.8.1
VMware Tanzu Operations Manager - addressed in versions 2.10.59, 3.0.12
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.0
Red Hat Advanced Cluster Security for Kubernetes - update to 4.0.5
Red Hat OpenShift Container Platform - addressed in versions 4.11.54, 4.12.45, 4.13.24, 4.14.4
OpenShift Virtualization - update to 4.12.9
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.13.3, 4.14.0
Node Maintenance Operator - update to 5.0.1
Red Hat Migration Toolkit for Applications - update to 6.2.1
AMQ Broker - update to 7.11.1
Red Hat OpenStack - update to 17.1.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.26, 23.0.1.4
libcap2-bin (Ubuntu package) - addressed in versions Ubuntu Pro, 1:2.32-1ubuntu0.1, 1:2.44-1ubuntu0.22.04.1, 1:2.44-1ubuntu0.22.10.1, 1:2.66-3ubuntu2.1
libcap2 (Ubuntu package) - addressed in versions Ubuntu Pro, 1:2.32-1ubuntu0.1, 1:2.44-1ubuntu0.22.04.1, 1:2.44-1ubuntu0.22.10.1, 1:2.66-3ubuntu2.1
DevWorkspace Operator - update to 0.22
ObjectScale - update to 1.4.0
Network Observability plugin for the Openshift Console - update to 1.4.0
Netcool Operations Insight - update to 1.6.12
IBM MQ Operator - addressed in versions 2.0.13, 2.4.2
Cloud Pak for Network Automation - update to 2.6.5
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
libcap-debugsource - addressed in versions 2.26-14.9.1, 2.26-150000.4.9.1, 2.63-150400.3.3.1
libcap-devel - addressed in versions 2.26-14.9.1, 2.26-150000.4.9.1, 2.63-150400.3.3.1
libcap-progs-debuginfo - addressed in versions 2.26-14.9.1, 2.26-150000.4.9.1, 2.63-150400.3.3.1
libcap2-debuginfo - addressed in versions 2.26-14.9.1, 2.26-150000.4.9.1, 2.63-150400.3.3.1
libcap2 - addressed in versions 2.26-14.9.1, 2.26-150000.4.9.1, 2.63-150400.3.3.1
libcap-progs - addressed in versions 2.26-14.9.1, 2.26-150000.4.9.1, 2.63-150400.3.3.1
libcap2-debuginfo-64bit - update to 2.26-14.9.1
libcap2-32bit - addressed in versions 2.26-14.9.1, 2.26-150000.4.9.1, 2.63-150400.3.3.1
libcap2-debuginfo-32bit - update to 2.26-14.9.1
pam_cap-32bit - update to 2.26-150000.4.9.1
libcap2-32bit-debuginfo - addressed in versions 2.26-150000.4.9.1, 2.63-150400.3.3.1
pam_cap - update to 2.26-150000.4.9.1
pam_cap-32bit-debuginfo - update to 2.26-150000.4.9.1
pam_cap-debuginfo - update to 2.26-150000.4.9.1
libcap-debugsource - addressed in versions 2.32-6, 2.61-5
libcap-devel - addressed in versions 2.32-6, 2.61-5
libcap - addressed in versions 2.32-6, 2.61-5
libcap-debuginfo - addressed in versions 2.32-6, 2.61-5
libcap-help - addressed in versions 2.32-6, 2.61-5
libcap - addressed in versions 2.48-5, 2.69-1
libcap-devel - addressed in versions 2.48-5, 2.69-1
libcap (Red Hat package) - addressed in versions 2.48-5.el8_8, 2.48-8.el9_0.1, 2.48-9.el9_2
libcap - addressed in versions 2.48-7.fc38, 2.48-8.fc39
libpsx2-32bit-debuginfo - update to 2.63-150400.3.3.1
libpsx2-32bit - update to 2.63-150400.3.3.1
libpsx2-debuginfo - update to 2.63-150400.3.3.1
libpsx2 - update to 2.63-150400.3.3.1
libcap-static - update to 2.69-1
IBM Cloud Transformation Advisor - update to 3.7.0
IBM Cloud Pak for Watson AIOps - update to 3.7.2
Red Hat OpenShift Dev Spaces - addressed in versions 3.15.0, 3.16.0, 3.17.0
Platform Automation Toolkit - addressed in versions 4.4.19, 5.0.0, 5.1.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.0
EMC ViPR SRM - update to 4.10.0.0
Dell EMC VxRail Appliance - update to 8.0.120
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 49, 8.11.0.1 Interim fix 26, 8.12.0 Interim fix 8
IBM supplied MQ Advanced container images - update to 9.3.0.10-r1
Dell PowerProtect Cyber Recovery - update to 19.14.0.2
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.11, 23.0.12
Junos cRPD - update to 23.4R1
Juniper Cloud Native Router - update to 23.4R1

External References

Related Security Bulletins