Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in the iTop IT service management tool could allow unauthenticated users to execute code by deleting a specific file created during setup. This could potentially lead to unauthorized access or control over affected systems.
- Unauthorized code execution via file deletion.
- Impacts IT service management operations.
- Confirm relevance and exposure.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can exploit this vulnerability by interacting with the iTop web interface. This interaction allows them to delete a critical configuration file, which in turn enables further malicious actions leading to code execution.
- No authentication required.
- Delete the .readonly file.
- Code execution.
Live Threat
Current exploitation, exposure, and threat context
Prior to version 3.2.3, unauthenticated users could potentially execute code by deleting a file that normally prevents write actions on Combodo iTop instances. This could affect the integrity and availability of the service.
- System files could be deleted.
- Unauthenticated network access could trigger deletion.
- Service integrity and availability may be impacted.
Operational Fix
Recommended remediation, mitigation, and detection steps
The iTop application owner, likely within IT Operations or a dedicated application support team, is responsible for managing this vulnerability. The first practical step is to confirm the presence and exposure of iTop instances, identify business-critical deployments, and then coordinate remediation.
- Ownership: Application owners must address this.
- Verify first: Confirm iTop presence and exposure.
- Action: Plan and schedule remediation.