Solaris SNMP Vulnerability
BID:177
Info
Solaris SNMP Vulnerability
| Bugtraq ID: | 177 |
| Class: | Access Validation Error |
| CVE: |
CVE-1999-0186 |
| Remote: | No |
| Local: | No |
| Published: | Aug 12 1998 12:00AM |
| Updated: | Jul 11 2009 12:16AM |
| Credit: | ISS Security Update November 16th, 1998 Hidden community string in SNMP implementation |
| Vulnerable: |
Sun Solaris 2.5.1 _x86 Sun Solaris 2.5.1 Sun Solaris 2.6_x86 Sun Solaris 2.6 Sun Solaris 2.5_x86 Sun Solaris 2.4_x86 Sun Solaris 2.4 |
| Not Vulnerable: | |
Discussion
Solaris SNMP Vulnerability
The Solstice Enterprise Agents (SEA) enables the creation of custom, extensible agents for device and system management for Solaris. SEA supports both the Simple Network Management Protocol (SNMP) and DMI protocols.
A default community string is present in the Sun SNMP subagent that may be remotely exploited by an unauthorized user to modify system parameters or execute arbitrary commands with root privileges.
SEA was initially available as an unbundled product and later bundled
with Solaris 2.6 at version 1.0.1.
The Solstice Enterprise Agents (SEA) enables the creation of custom, extensible agents for device and system management for Solaris. SEA supports both the Simple Network Management Protocol (SNMP) and DMI protocols.
A default community string is present in the Sun SNMP subagent that may be remotely exploited by an unauthorized user to modify system parameters or execute arbitrary commands with root privileges.
SEA was initially available as an unbundled product and later bundled
with Solaris 2.6 at version 1.0.1.
Exploit / POC
Solaris SNMP Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Solaris SNMP Vulnerability
References:
References: