Data Center Resources Avocent CCM Privileged Port Access Bypass Vulnerability
BID:14853
Info
Data Center Resources Avocent CCM Privileged Port Access Bypass Vulnerability
| Bugtraq ID: | 14853 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2005 12:00AM |
| Updated: | Sep 15 2005 12:00AM |
| Credit: | Dirk Wetter is credited with the discovery of this vulnerability. |
| Vulnerable: |
Data Center Resources Avocent CCM4850 2.1 (Firmware) |
| Not Vulnerable: |
Data Center Resources Avocent CCM4850 2.3 (Firmware) |
Discussion
Data Center Resources Avocent CCM Privileged Port Access Bypass Vulnerability
Avocent CCM is prone to a vulnerability that permits the bypass of access control to privileged ports. This issue is due to a failure in the application to perform proper authorization before granting access to internal functions.
An attacker can exploit this vulnerability to bypass access control and gain privileged access to ports and devices connected to the vulnerable appliance.
Avocent CCM is prone to a vulnerability that permits the bypass of access control to privileged ports. This issue is due to a failure in the application to perform proper authorization before granting access to internal functions.
An attacker can exploit this vulnerability to bypass access control and gain privileged access to ports and devices connected to the vulnerable appliance.
Exploit / POC
Data Center Resources Avocent CCM Privileged Port Access Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Data Center Resources Avocent CCM Privileged Port Access Bypass Vulnerability
Solution:
Reports indicate the vendor has addressed this issue in firmware version 2.3 for the affected device; this has not been confirmed by Symantec or the vendor.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Data Center Resources Avocent CCM4850 2.1 (Firmware)
Solution:
Reports indicate the vendor has addressed this issue in firmware version 2.3 for the affected device; this has not been confirmed by Symantec or the vendor.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Data Center Resources Avocent CCM4850 2.1 (Firmware)
-
Data Center Resources CCM4850_AV_2.3.zip
ftp://ftp.avocent.com/public/product-upgrades/$ds1800/CCMx50%20Series/ CCMx50%27s_AV_2.3/CCM4850_AV_2.3/CCM4850_AV_2.3.zip
References
Data Center Resources Avocent CCM Privileged Port Access Bypass Vulnerability
References:
References:
- Avocent CCM Console Homepage (Data Center Resources)
- Avocent CCM: Port Access Control Bypass Vulnerability ([email protected])