PT-2012-3767 · F5 · F5 Firepass
Publicado
2012-04-04
·
Atualizado
2017-12-20
·
CVE-2012-2053
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
F5 FirePass versions 6.0.0 through 6.1.0
F5 FirePass version 7.0.0
Description
The issue concerns the sudoers file in the Linux system configuration, which does not require a password for executing commands as root. This allows local users to gain privileges via the sudo program. For example, a user account that executes PHP scripts can exploit this issue.
Recommendations
For F5 FirePass versions 6.0.0 through 6.1.0, update the sudoers file to require a password for executing commands as root.
For F5 FirePass version 7.0.0, update the sudoers file to require a password for executing commands as root.
As a temporary workaround, consider restricting access to the sudo program until a patch is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
F5 Firepass