PT-2008-1519 · Nantsys+1 · Nantsys Device+1
Publicado
2008-01-09
·
Atualizado
2017-07-29
·
CVE-2007-5761
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Motorola netOctopus version 5.1.2 build 1011
NantSys device version 5.0.0.115
Description
The issue concerns weak permissions for the NantSys device interface, allowing local users to gain privileges or cause a denial of service, resulting in a system crash. This can be achieved by modifying the SYSENTER EIP MSR CPU Model Specific Register (MSR) value.
Recommendations
For Motorola netOctopus version 5.1.2 build 1011, consider restricting access to the NantSys device interface to prevent local users from gaining privileges or causing a denial of service.
For NantSys device version 5.0.0.115, restrict modifications to the SYSENTER EIP MSR CPU Model Specific Register (MSR) value to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Nantsys Device
Netoctopus