PT-2015-1275 · Infoblox · Infoblox Netmri
Published
2015-02-20
·
Updated
2016-11-30
·
CVE-2015-2033
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Infoblox Network Automation NetMRI versions prior to NETMRI-23483
Description
The issue is related to a flaw in the authentication procedure of the NetMRI network monitoring program in the Anyterm Daemon. This flaw allows remote attackers to execute arbitrary commands with root privileges via crafted terminal/anyterm-module requests. Exploitation of this issue may enable a remote attacker to execute arbitrary code using specially formed requests.
Recommendations
For versions prior to NETMRI-23483, update to a version that includes the fix for this issue, specifically NETMRI-23483 or later. As a temporary workaround, consider restricting access to the Anyterm Daemon to minimize the risk of exploitation. Avoid using the Anyterm Daemon until the issue is resolved.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Infoblox Netmri