Add CVE triage and disposition artifacts for scan hits

This commit is contained in:
beatz174-bit
2026-04-13 10:38:15 +10:00
parent 7817122265
commit 60c1719b6d
18 changed files with 818 additions and 0 deletions
@@ -0,0 +1,127 @@
{
"host": "prometheus.lan.ddnsgeek.com",
"generated_at": "2026-04-07T03:49:38.723646+00:00",
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
"findings": [
{
"host": "prometheus.lan.ddnsgeek.com",
"cve": "CVE-2009-3733",
"affected_host": "prometheus.lan.ddnsgeek.com",
"endpoint": "/sdk/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/etc/vmware/hostd/vmInventory.xml",
"product_version_evidence": [
"No explicit product/version fingerprint in nmap service line."
],
"exploit_precondition": "Target must expose VMware SDK endpoint (/sdk) and allow traversal into host files.",
"reproducibility": "not-reproduced",
"disposition": "not-applicable",
"disposition_rationale": "Only unauthorized responses were observed; vulnerable behavior was not reproduced and signature is likely a false positive.",
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
"evidence_sources": [
{
"file": "results/prometheus.lan.ddnsgeek.com/scans/_patterns.log",
"match_count": 2
},
{
"file": "results/prometheus.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt",
"endpoint": "/sdk/../../../../../../../etc/vmware/hostd/vmInventory.xml",
"evidence": "Possible path traversal in VMWare (CVE-2009-3733) (401 Unauthorized)"
},
{
"file": "results/prometheus.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt",
"endpoint": "/sdk/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/etc/vmware/hostd/vmInventory.xml",
"evidence": "Possible path traversal in VMWare (CVE-2009-3733) (401 Unauthorized)"
}
]
},
{
"host": "prometheus.lan.ddnsgeek.com",
"cve": "CVE-2011-0966",
"affected_host": "prometheus.lan.ddnsgeek.com",
"endpoint": "/cwhp/auditLog.do?file=..\\..\\..\\..\\..\\..\\..\\Program%20Files\\CSCOpx\\MDC\\Tomcat\\webapps\\triveni\\WEB-INF\\classes\\schedule.properties",
"product_version_evidence": [
"No explicit product/version fingerprint in nmap service line."
],
"exploit_precondition": "Target must be Cisco Unified Operations Manager 8.0/8.5 with vulnerable auditLog.do traversal handling.",
"reproducibility": "not-reproduced",
"disposition": "not-applicable",
"disposition_rationale": "Only unauthorized responses were observed; vulnerable behavior was not reproduced and signature is likely a false positive.",
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
"evidence_sources": [
{
"file": "results/prometheus.lan.ddnsgeek.com/scans/_patterns.log",
"match_count": 4
},
{
"file": "results/prometheus.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt",
"endpoint": "/cwhp/auditLog.do?file=..\\..\\..\\..\\..\\..\\..\\boot.ini",
"evidence": "Possible CiscoWorks (CuOM 8.0 and 8.5) Directory traversal (CVE-2011-0966) (Windows) (401 Unauthorized)"
},
{
"file": "results/prometheus.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt",
"endpoint": "/cwhp/auditLog.do?file=..\\..\\..\\..\\..\\..\\..\\Program%20Files\\CSCOpx\\MDC\\Tomcat\\webapps\\triveni\\WEB-INF\\classes\\schedule.properties",
"evidence": "Possible CiscoWorks (CuOM 8.0 and 8.5) Directory traversal (CVE-2011-0966) (Windows) (401 Unauthorized)"
},
{
"file": "results/prometheus.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt",
"endpoint": "/cwhp/auditLog.do?file=..\\..\\..\\..\\..\\..\\..\\Program%20Files\\CSCOpx\\lib\\classpath\\com\\cisco\\nm\\cmf\\dbservice2\\DBServer.properties",
"evidence": "Possible CiscoWorks (CuOM 8.0 and 8.5) Directory traversal (CVE-2011-0966) (Windows) (401 Unauthorized)"
},
{
"file": "results/prometheus.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt",
"endpoint": "/cwhp/auditLog.do?file=..\\..\\..\\..\\..\\..\\..\\Program%20Files\\CSCOpx\\log\\dbpwdChange.log",
"evidence": "Possible CiscoWorks (CuOM 8.0 and 8.5) Directory traversal (CVE-2011-0966) (Windows) (401 Unauthorized)"
}
]
},
{
"host": "prometheus.lan.ddnsgeek.com",
"cve": "CVE-2018-10822",
"affected_host": "prometheus.lan.ddnsgeek.com",
"endpoint": "/uir//etc/passwd",
"product_version_evidence": [
"No explicit product/version fingerprint in nmap service line."
],
"exploit_precondition": "Target must be affected D-Link router firmware exposing /uir/ traversal path.",
"reproducibility": "not-reproduced",
"disposition": "not-applicable",
"disposition_rationale": "Only unauthorized responses were observed; vulnerable behavior was not reproduced and signature is likely a false positive.",
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
"evidence_sources": [
{
"file": "results/prometheus.lan.ddnsgeek.com/scans/_patterns.log",
"match_count": 1
},
{
"file": "results/prometheus.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt",
"endpoint": "/uir//etc/passwd",
"evidence": "Possible D-Link router directory traversal vulnerability (CVE-2018-10822) (401 Unauthorized)"
}
]
},
{
"host": "prometheus.lan.ddnsgeek.com",
"cve": "CVE-2018-10824",
"affected_host": "prometheus.lan.ddnsgeek.com",
"endpoint": "/uir//tmp/csman/0",
"product_version_evidence": [
"No explicit product/version fingerprint in nmap service line."
],
"exploit_precondition": "Target must be affected D-Link router firmware exposing plaintext credential path under /tmp/csman.",
"reproducibility": "not-reproduced",
"disposition": "not-applicable",
"disposition_rationale": "Only unauthorized responses were observed; vulnerable behavior was not reproduced and signature is likely a false positive.",
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
"evidence_sources": [
{
"file": "results/prometheus.lan.ddnsgeek.com/scans/_patterns.log",
"match_count": 1
},
{
"file": "results/prometheus.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt",
"endpoint": "/uir//tmp/csman/0",
"evidence": "Possible D-Link router plaintext password file exposure (CVE-2018-10824) (401 Unauthorized)"
}
]
}
]
}