Description
The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312) to read arbitrary files with kluser privileges.
In plain language
AI Worth attentionThis bug in Kaspersky Anti-Virus for Linux File Server lets an attacker use the web interface to read any file on the server without a login, so you should treat it as an active security risk if you expose the web interface to the internet.
Unauthenticated network abuse of the Kaspersky Anti-Virus for Linux File Server web interface allows attackers to manipulate the reportId parameter in the getReportStatus action method to read arbitrary files with limited server privileges.
What to do now
- Check whether your Kaspersky Anti-Virus for Linux File Server version is before “Maintenance Pack 2 Critical Fix 4 (8.0.4.312)”.
- Check whether the product’s web interface is reachable from outside your network (for example, accessible from the internet or from untrusted networks).
- If it is reachable or you’re unsure, immediately restrict access to the web interface to only trusted IPs or internal networks.
- Upgrade/apply the fix to Maintenance Pack 2 Critical Fix 4 (8.0.4.312) or later, following your vendor’s upgrade guidance.
- After upgrading, monitor for unusual web requests to the getReportStatus area and review logs for abnormal attempts to access report/status endpoints.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-9812 and every CVE in our database. Create a free account — no credit card required.
Create Free Account