External risk intelligence

QiAnXin TianQing Management Center Arbitrary File Upload Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2024-13984

The vulnerability resides in a central management console product, which typically functions as an administrative web application. Given that the vulnerable rptsvr component provides an upload endpoint accessible via standard web requests, such management platforms are commonly deployed as network-accessible services to facilitate remote administration and monitoring.

Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability impacts management software, allowing unauthorized file uploads to critical server locations. This could potentially lead to system compromise and unauthorized code execution. The primary concern is to confirm if this specific management technology is in use within our environment.

  • Unauthenticated file uploads to arbitrary server locations.
  • Impacts management software, a central control point.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can reach the vulnerability by sending a specially crafted request to the upload endpoint of the rptsvr component. This component is exposed externally and does not require authentication. By manipulating the filename parameter in the request, an attacker can traverse directories and upload malicious files to arbitrary locations on the server, which can then be executed.

  • No authentication needed.
  • Filename parameter manipulation.
  • Remote code execution risk.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to upload executable files to web-accessible directories on the server, potentially leading to remote code execution. This could occur when the server is running the vulnerable rptsvr component and an attacker sends a specially crafted request to the upload endpoint.

  • Server files and directories at risk.
  • Upload files to arbitrary server locations.
  • Potential for remote code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical path traversal vulnerability in the QiAnXin TianQing Management Center's rptsvr component requires immediate attention from teams responsible for application security and infrastructure. The first practical step is to identify all instances of this management center within your environment, confirm their network reachability and business criticality, and then locate the accountable system owner for coordinated remediation planning.

  • Application owners or platform teams should own the issue.
  • Verify network exposure and business criticality.
  • Plan vendor-coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is QiAnXin TianQing Management Center?

It is a centralized management platform designed to oversee and monitor endpoint security and infrastructure across an organization. It acts as a command console for administrators to manage security policies and system status. The vulnerability specifically affects the 'rptsvr' component, which serves as a back-end utility for handling reporting and data processing tasks within the management suite.

What is the vulnerability in CVE-2024-13984?

This is a path traversal vulnerability classified as CWE-22. It occurs because the software fails to properly check file names provided during an upload process. By manipulating the file path, an attacker can bypass intended directory restrictions, effectively writing files to unintended or sensitive locations on the server's file system rather than the designated upload folder.

How does an attacker trigger this bug?

An attacker triggers the issue by sending a specially crafted multipart form-data request to the '/rptsvr/upload' endpoint. Because this endpoint does not require authentication, the attacker can submit a request containing a manipulated filename parameter to initiate the traversal. Importantly, this does not require any specialized user interaction, as the endpoint is designed to accept file uploads directly via standard web requests.

Do I need to worry if my instance is internal?

According to Halo Surface Signal, management consoles like this are typically deployed as network-accessible services to enable remote administration, which increases the likelihood of exposure. While internal instances face a lower risk from internet-based attackers, they remain vulnerable to any malicious actor or compromised device already present within your internal network segment.

What are the first steps to address this?

Start by identifying all servers running the QiAnXin TianQing Management Center in your environment. Once identified, confirm the network accessibility and business purpose of each instance. Finally, contact the designated system owner for these platforms to ensure the software is on your patching schedule and coordinated for the appropriate remediation steps provided by the vendor.

References