PT-2008-1519 · Nantsys+1 · Nantsys Device+1
Published
2008-01-09
·
Updated
2017-07-29
·
CVE-2007-5761
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Motorola netOctopus version 5.1.2 build 1011
NantSys device version 5.0.0.115
Description
The issue concerns weak permissions for the NantSys device interface, allowing local users to gain privileges or cause a denial of service, resulting in a system crash. This can be achieved by modifying the SYSENTER EIP MSR CPU Model Specific Register (MSR) value.
Recommendations
For Motorola netOctopus version 5.1.2 build 1011, consider restricting access to the NantSys device interface to prevent local users from gaining privileges or causing a denial of service.
For NantSys device version 5.0.0.115, restrict modifications to the SYSENTER EIP MSR CPU Model Specific Register (MSR) value to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nantsys Device
Netoctopus