PT-2005-3068 · Raritan · Raritan Dominion Sx
Dr. Dirk Wetter
·
Published
2005-07-05
·
Updated
2023-04-25
·
CVE-2005-2136
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Raritan Dominion SX (DSX) Console Servers versions DSX16, DSX32, DSX4, DSX8, and DSXA-48
Description:
The issue allows local users to obtain hashed passwords or execute arbitrary code as other users due to world-readable permissions for /etc/shadow and world-writable permissions for /bin/busybox.
Recommendations:
For versions DSX16, DSX32, DSX4, DSX8, and DSXA-48, consider changing the permissions of /etc/shadow to prevent world-readable access and restrict write access to /bin/busybox to prevent arbitrary code execution.
As a temporary workaround, consider restricting access to the /bin/busybox executable until a patch is available.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Raritan Dominion Sx