Horizon Alert
Summary of the vulnerability and why it matters
Certain installations of Gladinet CentreStack and TrioFox are susceptible to a vulnerability that could lead to the unauthorized exposure of system files. This flaw allows attackers to access sensitive information without requiring any authentication. Exploitation of this vulnerability has been observed.
- Gladinet CentreStack and TrioFox software
- Unauthenticated access to system files
- Unintended disclosure of sensitive data
Attack Path
How an attacker could exploit the issue
This vulnerability allows an attacker to access sensitive system files on the affected organizations' servers. Exploitation has been observed in real-world attacks, posing a risk to data confidentiality. The unauthenticated nature of the flaw means attackers do not need prior access to the system.
- Unauthenticated access to the system.
- Attacker triggers file disclosure.
- Unintended disclosure of system files.
Live Threat
Current exploitation, exposure, and threat context
The identified vulnerability presents a significant risk due to its unauthenticated nature, allowing for the unintended disclosure of system files. Exploitation in the wild has been documented, indicating that malicious actors are actively targeting this weakness. The ease of exploitation and the potential for sensitive data exposure necessitate prompt attention to mitigate business risk.
- Attackers need no special skills.
- No access or conditions required.
- High business risk and urgency.
Priority actions
Operational Fix
Recommended remediation, mitigation, and detection steps
An unauthenticated Local File Inclusion vulnerability has been identified in Gladinet CentreStack and TrioFox, allowing for unintended disclosure of system files. Exploitation of this flaw has been observed in the wild, posing a risk to affected organizations. The vulnerability impacts all versions prior to and including 16.7.10368.56560 for TrioFox and all versions prior to 16.10.10408.56683 for CentreStack.
- Find affected assets.
- Reduce exposure or isolate risk.
- Fix, verify, and monitor.