Intel Southbridge 2 Baseboard Management Controller Remote Denial of Service Vulnerability
BID:22341
Info
Intel Southbridge 2 Baseboard Management Controller Remote Denial of Service Vulnerability
| Bugtraq ID: | 22341 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-0661 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 31 2007 12:00AM |
| Updated: | May 12 2015 07:34PM |
| Credit: | Keith Josephson of ION Computer Systems, Inc reported this issue to the vendor. |
| Vulnerable: |
Intel Enterprise Southbridge 2 BMC Firmware 0.56 Intel Enterprise Southbridge 2 BMC Firmware 0 |
| Not Vulnerable: |
Intel Enterprise Southbridge 2 BMC Firmware 0.57 |
Discussion
Intel Southbridge 2 Baseboard Management Controller Remote Denial of Service Vulnerability
Intel Enterprise Southbridge 2 Baseboard Management Controllers are prone to a remote denial-of-service vulnerability because the devices fail to properly restrict remote access to authorized users.
Successfully exploiting this issue allows remote attackers to gain network-based access to the Baseboard Management Controller for Intelligent Platform Management Interface. By issuing commands to this interface, attackers can trigger denial-of-service conditions, but they cannot gain access to the operating system or data contained in affected computers.
Firmware versions prior to release 57 are vulnerable to this issue.
Intel Enterprise Southbridge 2 Baseboard Management Controllers are prone to a remote denial-of-service vulnerability because the devices fail to properly restrict remote access to authorized users.
Successfully exploiting this issue allows remote attackers to gain network-based access to the Baseboard Management Controller for Intelligent Platform Management Interface. By issuing commands to this interface, attackers can trigger denial-of-service conditions, but they cannot gain access to the operating system or data contained in affected computers.
Firmware versions prior to release 57 are vulnerable to this issue.
Exploit / POC
Intel Southbridge 2 Baseboard Management Controller Remote Denial of Service Vulnerability
Attackers use readily available network-management utilities to exploit this issue.
Attackers use readily available network-management utilities to exploit this issue.
Solution / Fix
Intel Southbridge 2 Baseboard Management Controller Remote Denial of Service Vulnerability
Solution:
Intel has released an advisory and updated firmware to address this issue. Please see the references for more information on obtaining and applying fixes.
Solution:
Intel has released an advisory and updated firmware to address this issue. Please see the references for more information on obtaining and applying fixes.
References
Intel Southbridge 2 Baseboard Management Controller Remote Denial of Service Vulnerability
References:
References: