← Back to all advisories
High

HtmlImport Unauthenticated Remote Code Execution

Advisory ID
L9-16-482
Category
Unrestricted Upload of File with Dangerous Type
Vendor
Priva
Product
Priva Office Direct
Affected Version
9.0.0
First Published
August 19, 2021
Last Updated
January 22, 2024
Impact
High

Risk Summary

The Priva Office Direct software is used to interface with the Priva process computer in horticultural operations and smart greenhouses. Through this interface, operators monitor and modify set points such as temperature, curtain, humidity, dosing, and flow rates. The application contains an unauthenticated import function that can be abused to execute code on the underlying operating system. The research team identified this in the application bytecode and exploited it using directory traversal and a null byte in the file path, injecting a Java Servlet Page (JSP) file that is run by the server.

Technical Details

The research team identified this issue within the '/office/user/HtmImport' URL. The query parameter 'screenId' is used to indicate a file path. Typically this path contains a local HTML file used as a UI rendering view, and the body of the request contains the content of that file.

The team manipulated the 'screenId' parameter using a directory traversal vulnerability and a null byte injection. In combination, these allow a JSP file to be placed within the web root of the Tomcat application. A JSP file is not typically allowed within the HtmlImport function, but the use of a null byte (%00) at the end of the parameter value truncates this verification.

../../../../../../Program%20Files/Priva/Priva%20Office/WebServer/webapps/books/x.jsp%00

This places a JSP file named 'x.jsp' within the default 'books' webapp. Placing the file within the web root enables a threat actor to access and execute its contents over the network. In this instance, a simple reverse shell was executed to demonstrate the capability.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
Platform OverviewDigital TwinAutonomous TestingExploitability VerificationVulnerability GraphRemediation OptimizationELTON TestLink™Lifecycle & MetricsCVSSv4 MigrationProduct Tour
Solutions
FDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLWPostmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory Affairs
Why ELTON
Why ELTONProof Over ProbabilityFind the 1%Not a Pentest. Not a Scanner.MDDT MethodologyCredentialsDevice ModalitiesPricingELTON vs. Consultants
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRegulatory GuidesWebinarsThe Death of PentestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersContact Book a Demo