PT-2018-10272 · Dell Emc · Dell Idrac Service Module

Publicado

2018-06-26

·

Atualizado

2021-06-10

·

CVE-2018-11053

CVSS v3.1

6.6

Média

VetorAV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Dell EMC iDRAC Service Module versions v3.0.1, v3.0.2, v3.1.0, v3.2.0
Description The issue allows a malicious low privileged operating system user or process to modify the host file and potentially redirect traffic from the intended destination to sites hosting malicious or unwanted content. This occurs because the Dell EMC iDRAC Service Module changes the default file permission of the hosts file of the host operating system (/etc/hosts) to world writable when started.
Recommendations For versions v3.0.1, v3.0.2, v3.1.0, v3.2.0, consider changing the file permission of the /etc/hosts file to prevent world writable access until a patch is available. As a temporary workaround, restrict access to the /etc/hosts file to minimize the risk of exploitation.

Correção

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-11053

Produtos afetados

Dell Idrac Service Module