CVE-2017-20217
7.5Serviio · Serviio PRO
Serviio PRO contains an information disclosure vulnerability in its Configuration REST API that allows unauthenticated attackers to retrieve sensitive configuration data.
Executive summary
An unauthenticated information disclosure vulnerability in the Serviio PRO REST API allows remote attackers to access sensitive configuration data and credentials.
Vulnerability
The application fails to enforce proper access control on its Configuration REST API. This allows unauthenticated remote attackers to send specially crafted HTTP requests to retrieve sensitive system information, including administrative passwords.
Business impact
The exploitation of this vulnerability can lead to a complete compromise of the media server configuration and credentials. Given the CVSS score of 7.5, this is a high severity issue that facilitates unauthorized access to sensitive data, potentially allowing an attacker to pivot into the host system or gain control over the media streaming environment.
Remediation
Immediate Action: As there is no confirmed patch available, administrators should immediately restrict network access to the Serviio REST API endpoints to trusted internal IP addresses only.
Proactive Monitoring: Review web server and application access logs for unusual requests directed at the /rest/ path, particularly those attempting to access remote-access or list-folders endpoints.
Compensating Controls: Deploy a Web Application Firewall (WAF) or an edge firewall rule to block unauthorized access to the Serviio management ports.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in ExploitDB (EDB-ID 41958) and Packet Storm Security.
Analyst recommendation
Due to the availability of public exploit code and the ease of access to sensitive credentials, this vulnerability poses a significant risk to any exposed Serviio installation. Organizations must prioritize restricting network access to the affected API endpoints immediately to prevent unauthorized data retrieval.
More Serviio CVEs
Sources
Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.
- Zero Science Lab Disclosure Third-party advisory
- SecuriTeam Blogs Third-party advisory
- Exploit-DB Exploit / PoC
- CXSecurity Third-party advisory
- Packet Storm Security Exploit / PoC
- SecurityLab Third-party advisory
- IBM X-Force Exchange Vulnerability database entry
- VulnCheck Advisory: Serviio PRO 1.8 REST API Information Disclosure Third-party advisory