IP3 NetAccess Local Privilege Escalation Vulnerability
BID:36410
Info
IP3 NetAccess Local Privilege Escalation Vulnerability
| Bugtraq ID: | 36410 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 15 2009 12:00AM |
| Updated: | Sep 16 2009 05:40PM |
| Credit: | r00t |
| Vulnerable: |
IP3 Networks NA75 4.0.34 firmware IP3 Networks NA 4.1.9.6 IP3 Networks NA 4.0 IP3 Networks IP3 NetAccess - Wireless ISPs & MDUs 4.0.34 firmware IP3 Networks IP3 NetAccess - Wireless ISPs & MDUs 3.1.18 b13 firmware IP3 Networks IP3 NetAccess - Wireless ISPs & MDUs IP3 Networks IP3 NetAccess - Wireless HotZones & Small Hotels 4.0.34 firmware IP3 Networks IP3 NetAccess - Wireless HotZones & Small Hotels 3.1.18 b13 firmware IP3 Networks IP3 NetAccess - Wireless HotZones & Small Hotels IP3 Networks IP3 NetAccess - Wireless HotSpots 4.0.34 firmware IP3 Networks IP3 NetAccess - Wireless HotSpots 3.1.18 b13 firmware IP3 Networks IP3 NetAccess - Wireless HotSpots IP3 Networks IP3 NetAccess - Hospitality 4.0.34 firmware IP3 Networks IP3 NetAccess - Hospitality 3.1.18 b13 firmware IP3 Networks IP3 NetAccess - Hospitality IP3 Networks IP3 NetAccess - Campus and MDUs 4.0.34 firmware IP3 Networks IP3 NetAccess - Campus and MDUs 3.1.18 b13 firmware IP3 Networks IP3 NetAccess - Campus and MDUs |
| Not Vulnerable: | |
Discussion
IP3 NetAccess Local Privilege Escalation Vulnerability
IP3 NetAccess is prone to a local privilege-escalation vulnerability because it fails to sanitize user-supplied data.
An attacker can exploit this issue to run arbitrary commands and gain superuser privileges. Successful attacks will completely compromise affected devices.
IP3 NetAccess is prone to a local privilege-escalation vulnerability because it fails to sanitize user-supplied data.
An attacker can exploit this issue to run arbitrary commands and gain superuser privileges. Successful attacks will completely compromise affected devices.
Exploit / POC
IP3 NetAccess Local Privilege Escalation Vulnerability
An attacker can exploit this issue by supplying commands through the device's command-line interface.
An attacker can exploit this issue by supplying commands through the device's command-line interface.
Solution / Fix
IP3 NetAccess Local Privilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. The vendor has ceased to operate and may not provide fixes.
Solution:
Currently we are not aware of any vendor-supplied patches. The vendor has ceased to operate and may not provide fixes.