PT-2012-3767 · F5 · F5 Firepass
Published
2012-04-04
·
Updated
2017-12-20
·
CVE-2012-2053
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
F5 FirePass versions 6.0.0 through 6.1.0
F5 FirePass version 7.0.0
Description
The issue concerns the sudoers file in the Linux system configuration, which does not require a password for executing commands as root. This allows local users to gain privileges via the sudo program. For example, a user account that executes PHP scripts can exploit this issue.
Recommendations
For F5 FirePass versions 6.0.0 through 6.1.0, update the sudoers file to require a password for executing commands as root.
For F5 FirePass version 7.0.0, update the sudoers file to require a password for executing commands as root.
As a temporary workaround, consider restricting access to the sudo program until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
F5 Firepass