PT-2018-10272 · Dell Emc · Dell Idrac Service Module
Publicado
2018-06-26
·
Atualizado
2021-06-10
·
CVE-2018-11053
CVSS v3.1
6.6
Média
| Vetor | AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Dell EMC iDRAC Service Module versions v3.0.1, v3.0.2, v3.1.0, v3.2.0
Description
The issue allows a malicious low privileged operating system user or process to modify the host file and potentially redirect traffic from the intended destination to sites hosting malicious or unwanted content. This occurs because the Dell EMC iDRAC Service Module changes the default file permission of the hosts file of the host operating system (
/etc/hosts) to world writable when started.Recommendations
For versions v3.0.1, v3.0.2, v3.1.0, v3.2.0, consider changing the file permission of the
/etc/hosts file to prevent world writable access until a patch is available.
As a temporary workaround, restrict access to the /etc/hosts file to minimize the risk of exploitation.Correção
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Dell Idrac Service Module