PT-2005-3068 · Raritan · Raritan Dominion Sx

Dr. Dirk Wetter

·

Published

2005-07-05

·

Updated

2023-04-25

·

CVE-2005-2136

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Raritan Dominion SX (DSX) Console Servers versions DSX16, DSX32, DSX4, DSX8, and DSXA-48
Description: The issue allows local users to obtain hashed passwords or execute arbitrary code as other users due to world-readable permissions for /etc/shadow and world-writable permissions for /bin/busybox.
Recommendations: For versions DSX16, DSX32, DSX4, DSX8, and DSXA-48, consider changing the permissions of /etc/shadow to prevent world-readable access and restrict write access to /bin/busybox to prevent arbitrary code execution. As a temporary workaround, consider restricting access to the /bin/busybox executable until a patch is available.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2005-2136

Affected Products

Raritan Dominion Sx