Lantronix Secure Console Server SCS820/SCS1620 Multiple Local Vulnerabilities
BID:14486
Info
Lantronix Secure Console Server SCS820/SCS1620 Multiple Local Vulnerabilities
| Bugtraq ID: | 14486 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 05 2005 12:00AM |
| Updated: | Aug 05 2005 12:00AM |
| Credit: | c0ntex <[email protected]> disclosed these vulnerabilities. |
| Vulnerable: |
Lantronix SCS820 Lantronix SCS1620 |
| Not Vulnerable: | |
Discussion
Lantronix Secure Console Server SCS820/SCS1620 Multiple Local Vulnerabilities
Lantronix Secure Console Server SCS820/SCS1620 devices are susceptible to multiple local vulnerabilities.
The first issue is an insecure default permission vulnerability. Attackers may exploit this vulnerability to write data to arbitrary files with superuser privileges. Other attacks are also possible.
The second issue is a directory traversal vulnerability in the command-line interface. Attackers may exploit this vulnerability to gain inappropriate access to the underlying operating system.
The third issue is a privilege escalation vulnerability in the command-line interface. Local users with 'sysadmin' access to the device can escape the command-line interface to gain superuser privileges in the underlying operating system.
The last issue is a buffer overflow vulnerability in the 'edituser' binary. Attackers may exploit this vulnerability to execute arbitrary machine code with superuser privileges.
The reporter of these issues states that firmware versions prior to 4.4 are vulnerable.
Lantronix Secure Console Server SCS820/SCS1620 devices are susceptible to multiple local vulnerabilities.
The first issue is an insecure default permission vulnerability. Attackers may exploit this vulnerability to write data to arbitrary files with superuser privileges. Other attacks are also possible.
The second issue is a directory traversal vulnerability in the command-line interface. Attackers may exploit this vulnerability to gain inappropriate access to the underlying operating system.
The third issue is a privilege escalation vulnerability in the command-line interface. Local users with 'sysadmin' access to the device can escape the command-line interface to gain superuser privileges in the underlying operating system.
The last issue is a buffer overflow vulnerability in the 'edituser' binary. Attackers may exploit this vulnerability to execute arbitrary machine code with superuser privileges.
The reporter of these issues states that firmware versions prior to 4.4 are vulnerable.
Exploit / POC
Lantronix Secure Console Server SCS820/SCS1620 Multiple Local Vulnerabilities
A proof of concept exploit is available for the 'edituser' buffer overflow:
A proof of concept exploit is available for the 'edituser' buffer overflow:
Solution / Fix
Lantronix Secure Console Server SCS820/SCS1620 Multiple Local Vulnerabilities
Solution:
The reporter of these issues states that firmware version 4.4 resolves these issues. Users of affected devices are advised to contact the vendor for further information.
Users may find updated firmware files at:
ftp://ftp.lantronix.com/pub/scs1620/
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The reporter of these issues states that firmware version 4.4 resolves these issues. Users of affected devices are advised to contact the vendor for further information.
Users may find updated firmware files at:
ftp://ftp.lantronix.com/pub/scs1620/
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Lantronix Secure Console Server SCS820/SCS1620 Multiple Local Vulnerabilities
References:
References: