← Back to all advisories
High

HtmlImport Unauthenticated Remote Code Execution

Advisory ID
L9-16-482
Category
Unrestricted Upload of File with Dangerous Type
Vendor
Priva
Product
Priva Office Direct
Affected Version
9.0.0
First Published
August 19, 2021
Last Updated
January 22, 2024
Impact
High

Risk Summary

The Priva Office Direct software is used to interface with the Priva process computer in horticultural operations and smart greenhouses. Through this interface, operators monitor and modify set points such as temperature, curtain, humidity, dosing, and flow rates. The application contains an unauthenticated import function that can be abused to execute code on the underlying operating system. The research team identified this in the application bytecode and exploited it using directory traversal and a null byte in the file path, injecting a Java Servlet Page (JSP) file that is run by the server.

Technical Details

The research team identified this issue within the '/office/user/HtmImport' URL. The query parameter 'screenId' is used to indicate a file path. Typically this path contains a local HTML file used as a UI rendering view, and the body of the request contains the content of that file.

The team manipulated the 'screenId' parameter using a directory traversal vulnerability and a null byte injection. In combination, these allow a JSP file to be placed within the web root of the Tomcat application. A JSP file is not typically allowed within the HtmlImport function, but the use of a null byte (%00) at the end of the parameter value truncates this verification.

../../../../../../Program%20Files/Priva/Priva%20Office/WebServer/webapps/books/x.jsp%00

This places a JSP file named 'x.jsp' within the default 'books' webapp. Placing the file within the web root enables a threat actor to access and execute its contents over the network. In this instance, a simple reverse shell was executed to demonstrate the capability.

Questions

Common questions about the Priva HtmlImport vulnerability.

What is the Priva Office Direct HtmlImport vulnerability?

The HtmlImport function in Priva Office Direct 9.0.0 accepts an unauthenticated import request that can be abused to run code on the underlying operating system. Advisory L9-16-482 rates the impact High. The research team found it in the application bytecode and exploited it with directory traversal and a null byte in the file path.

Does the Priva HtmlImport attack require a login?

No. Advisory L9-16-482 describes the import function as unauthenticated, so no valid credentials are needed to reach it. The category assigned is unrestricted upload of file with dangerous type, and the impact is listed as High for Priva Office Direct 9.0.0.

How does the HtmlImport exploit place a file on the server?

The screenId query parameter on the HtmImport URL names a file path, normally a local HTML file used to render a view. The research team combined directory traversal with a null byte at the end of the parameter, which truncates the check that blocks JSP files, and wrote a JSP into the default books webapp under the Tomcat web root.

What does Priva Office Direct control?

Priva Office Direct is the software operators use to interface with the Priva process computer in horticultural operations and smart greenhouses. Through it they monitor and modify set points such as temperature, curtain, humidity, dosing and flow rates. Advisory L9-16-482 covers version 9.0.0, first published on August 19, 2021.

What did the researchers achieve on the Priva server?

The advisory states that a simple reverse shell was executed to demonstrate the capability. Placing the JSP file inside the web root lets a threat actor access and execute its contents over the network, which the advisory describes as code execution on the underlying operating system.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON