Engenio Storage Controller Remote Denial Of Service Vulnerability
BID:11108
Info
Engenio Storage Controller Remote Denial Of Service Vulnerability
| Bugtraq ID: | 11108 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 04 2004 12:00AM |
| Updated: | Sep 04 2004 12:00AM |
| Credit: | Discovery is credited to Frank Denis. |
| Vulnerable: |
Storagetek D280 IBM DS4100 Engenio 5884 Storage Controller Engenio 4884 Storage Controller Engenio 2882 Storage Controller Engenio 2822 Storage Controller Brocade SilkWorm Fiber Channel Switch 2050 Brocade SilkWorm Fiber Channel Switch 2040 Brocade SilkWorm Fiber Channel Switch 2010 Brocade SilkWorm 3900 Brocade SilkWorm 3850 Brocade SilkWorm 3800 Brocade SilkWorm 3250 Brocade SilkWorm 3200 Brocade Fabric OS 3.1 Brocade Fabric OS 2.2 Brocade Fabric OS 2.1.2 |
| Not Vulnerable: | |
Discussion
Engenio Storage Controller Remote Denial Of Service Vulnerability
It is reported that hardware based on Engenio Storage Controllers are prone to a remote denial of service vulnerability. This could also result reportedly result in unrecoverable corruption of data.
Affected hardware includes Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches. Other devices may be affected such as other Storagetek and IBM FastT storage controllers, SGI, and Teradata storage controllers though this has not confirmed. The problem may exist in the underlying vxWorks operating system though this has also not been confirmed.
It is reported that hardware based on Engenio Storage Controllers are prone to a remote denial of service vulnerability. This could also result reportedly result in unrecoverable corruption of data.
Affected hardware includes Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches. Other devices may be affected such as other Storagetek and IBM FastT storage controllers, SGI, and Teradata storage controllers though this has not confirmed. The problem may exist in the underlying vxWorks operating system though this has also not been confirmed.
Exploit / POC
Engenio Storage Controller Remote Denial Of Service Vulnerability
The researcher who discovered this vulnerability has developed exploit code which is not publicly available or known to be circulating in the wild.
The researcher who discovered this vulnerability has developed exploit code which is not publicly available or known to be circulating in the wild.
Solution / Fix
Engenio Storage Controller Remote Denial Of Service Vulnerability
Solution:
It has been reported that Brocade will be releasing firmware version 3.2 to address this issue for affected Brocade SilkWorm Fiber Channel Switches. This has not been confirmed by Symantec.
---
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that Brocade will be releasing firmware version 3.2 to address this issue for affected Brocade SilkWorm Fiber Channel Switches. This has not been confirmed by Symantec.
---
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Engenio Storage Controller Remote Denial Of Service Vulnerability
References:
References:
- Disk Systems Product Page (Storagetek)
- Engenio Homepage (Engenio)
- IBM TotalStorage DS4000 series Product Page (IBM)
- Engenio/LSI Logic controllers denial of service/data corruption (Jedi/Sector One
)