Sun Integrated Lights-Out Manager (ILOM) Authentication Bypass Vulnerability
BID:31861
Info
Sun Integrated Lights-Out Manager (ILOM) Authentication Bypass Vulnerability
| Bugtraq ID: | 31861 |
| Class: | Design Error |
| CVE: |
CVE-2008-4722 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 21 2008 12:00AM |
| Updated: | May 07 2015 05:22PM |
| Credit: | Sun Microsystems |
| Vulnerable: |
Sun Sun Netra X4450 0 Sun Sun Netra X4250 0 Sun Sun Netra X4200 M2 0 Sun Sun Netra T5440 0 Sun Sun Netra T5220 0 Sun Sun Netra CP3260 0 Sun Sun Fire X4600 M2 0 Sun Sun Fire X4600 0 Sun Sun Fire X4540 0 Sun Sun Fire X4500 0 Sun Sun Fire X4450 0 Sun Sun Fire X4440 0 Sun Sun Fire X4250 0 Sun Sun Fire X4240 0 Sun Sun Fire X4200 M2 0 Sun Sun Fire X4200 0 Sun Sun Fire X4150 0 Sun Sun Fire X4140 0 Sun Sun Fire X4100 M2 0 Sun Sun Fire X4100 0 Sun Sun Fire X2250 0 Sun Sun Fire X2200 M2 Server 0 Sun Sun Blade X8450 0 Sun Sun Blade X8440 0 Sun Sun Blade X8420 0 Sun Sun Blade X8400 0 Sun Sun Blade X8000 P 0 Sun Sun Blade X8000 0 Sun Sun Blade X6450 0 Sun Sun Blade X6250 0 Sun Sun Blade X6220 0 Sun Sun Blade X6048 0 Sun Sun Blade X6000 0 Sun Sun Blade T6320 0 Sun SPARC Enterprise T5440 Server 0 Sun SPARC Enterprise T5240 Server 0 Sun SPARC Enterprise T5220 Server 0 Sun SPARC Enterprise T5140 Server 0 Sun SPARC Enterprise T5120 Server 0 |
| Not Vulnerable: | |
Discussion
Sun Integrated Lights-Out Manager (ILOM) Authentication Bypass Vulnerability
Sun Integrated Lights-Out Manager (ILOM) is prone to an authentication-bypass vulnerability caused by an unspecified error.
Attackers can exploit this vulnerability to gain access to the service processor (SP) through the web interface. This may allow attackers to perform actions that will result in denial-of-service conditions.
Note that to successfully exploit this issue, an attacker must have access to the ILOM web interface.
Sun Integrated Lights-Out Manager (ILOM) is prone to an authentication-bypass vulnerability caused by an unspecified error.
Attackers can exploit this vulnerability to gain access to the service processor (SP) through the web interface. This may allow attackers to perform actions that will result in denial-of-service conditions.
Note that to successfully exploit this issue, an attacker must have access to the ILOM web interface.
Exploit / POC
Sun Integrated Lights-Out Manager (ILOM) Authentication Bypass Vulnerability
Attackers will likely exploit this issue via a browser.
Attackers will likely exploit this issue via a browser.
Solution / Fix
Sun Integrated Lights-Out Manager (ILOM) Authentication Bypass Vulnerability
Solution:
The vendor released an advisory and fixes to address this issue. Please see the references for more information.
Sun Sun Netra T5440 0
Sun SPARC Enterprise T5120 Server 0
Sun Sun Blade T6320 0
Sun Sun Netra CP3260 0
Sun Sun Netra T5220 0
Sun SPARC Enterprise T5140 Server 0
Sun SPARC Enterprise T5240 Server 0
Sun SPARC Enterprise T5440 Server 0
Solution:
The vendor released an advisory and fixes to address this issue. Please see the references for more information.
Sun Sun Netra T5440 0
Sun SPARC Enterprise T5120 Server 0
Sun Sun Blade T6320 0
Sun Sun Netra CP3260 0
-
Sun 136935-03
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -136935-03-1 -
Sun 139280-02
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -139280-02-1
Sun Sun Netra T5220 0
Sun SPARC Enterprise T5140 Server 0
Sun SPARC Enterprise T5240 Server 0
Sun SPARC Enterprise T5440 Server 0
References
Sun Integrated Lights-Out Manager (ILOM) Authentication Bypass Vulnerability
References:
References:
- Sun Integrated Lights Out Manager Homepage (Sun Microsystems)
- Solution 243486: A Security Vulnerability in the Sun Integrated Lights-Out Manag (Sun Microsystems)