PT-2005-3068 · Raritan · Raritan Dominion Sx
Dr. Dirk Wetter
·
Publicado
2005-07-05
·
Atualizado
2023-04-25
·
CVE-2005-2136
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Raritan Dominion SX (DSX) Console Servers versions DSX16, DSX32, DSX4, DSX8, and DSXA-48
Description:
The issue allows local users to obtain hashed passwords or execute arbitrary code as other users due to world-readable permissions for /etc/shadow and world-writable permissions for /bin/busybox.
Recommendations:
For versions DSX16, DSX32, DSX4, DSX8, and DSXA-48, consider changing the permissions of /etc/shadow to prevent world-readable access and restrict write access to /bin/busybox to prevent arbitrary code execution.
As a temporary workaround, consider restricting access to the /bin/busybox executable until a patch is available.
Exploit
Correção
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Raritan Dominion Sx