LANDesk Management Gateway Multiple Security Vulnerabilities
BID:38119
Info
LANDesk Management Gateway Multiple Security Vulnerabilities
| Bugtraq ID: | 38119 |
| Class: | Unknown |
| CVE: |
CVE-2010-0368 CVE-2010-0369 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2010 12:00AM |
| Updated: | Feb 05 2010 12:00AM |
| Credit: | Aureliano Calvo and Adrian Manrique from Core Security Technologies |
| Vulnerable: |
LANDesk Software Landesk Management Gateway 4.2-1.8 LANDesk Software Landesk Management Gateway 4.0-1.48 |
| Not Vulnerable: |
LANDesk Software Landesk Management Gateway 4.2-1.61 LANDesk Software Landesk Management Gateway 4.0-1.61 |
Discussion
LANDesk Management Gateway Multiple Security Vulnerabilities
LANDesk Management Gateway is prone to a cross-site request-forgery vulnerability and a cross-site scripting vulnerability.
An attacker can exploit the cross-site request forgery issue to alter the settings on affected devices. This may lead to further network-based attacks, including command-injection attacks to the device's underlying operating system, which can lead to a complete compromise of a vulnerable device.
The attacker can exploit the cross-site scripting issue to execute arbitrary script code in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials. Other attacks are also possible.
LANDesk Management Gateway is prone to a cross-site request-forgery vulnerability and a cross-site scripting vulnerability.
An attacker can exploit the cross-site request forgery issue to alter the settings on affected devices. This may lead to further network-based attacks, including command-injection attacks to the device's underlying operating system, which can lead to a complete compromise of a vulnerable device.
The attacker can exploit the cross-site scripting issue to execute arbitrary script code in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials. Other attacks are also possible.
Exploit / POC
LANDesk Management Gateway Multiple Security Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example commands may be injected into the vulnerable parameter:
'a; sudo /subin/firewall stop'
'a; sudo /subin/modprobe /tmp/a_module'
The following proof-of-concept code is available:
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example commands may be injected into the vulnerable parameter:
'a; sudo /subin/firewall stop'
'a; sudo /subin/modprobe /tmp/a_module'
The following proof-of-concept code is available:
Solution / Fix
LANDesk Management Gateway Multiple Security Vulnerabilities
Solution:
The vendor has released updates. Please see the references for details.
Solution:
The vendor has released updates. Please see the references for details.
References
LANDesk Management Gateway Multiple Security Vulnerabilities
References:
References:
- LANDesk Management Gateway Homepage (LANDesk Software)
- CORE-2010-0104 - LANDesk OS command injection (CORE Security Technologies Advisories
) - LANDesk command injection (CORE Security Technologies)
- LANDesk Management Gateway GSB Software Vulnerability (LANDesk Software)