Alcatel OmniPCX Password File Encrypted Password Access Vulnerability
BID:4129
Info
Alcatel OmniPCX Password File Encrypted Password Access Vulnerability
| Bugtraq ID: | 4129 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 19 2002 12:00AM |
| Updated: | Feb 19 2002 12:00AM |
| Credit: | This vulnerability was announced in a Security Bugware Advisory on February 19, 2002. |
| Vulnerable: |
Alcatel-Lucent OmniPCX 4400 0 |
| Not Vulnerable: | |
Discussion
Alcatel OmniPCX Password File Encrypted Password Access Vulnerability
OmniPCX is an enterprise-level Personal Communications Exchange (PCX) system maintained and distributed by Alcatel.
By default, OmniPCX does not use shadowed passwords. While this is not inherently a vulnerability as OmniPCX systems are not designed for multi-user access, this problem can lead to issues such as local privilege access and elevation when combined with issues such as Bugtraq ID 4127, "Alcatel OmniPCX Default Passwords Vulnerability." If a remote user is able to gain access to the system via some unprivileged account, it is possible for the user to retrieve the encrypted password hashes and launch a brute force crack attack against them offline. This may be a Chorus OS problem, currently maintained by Sun Microsystems.
OmniPCX is an enterprise-level Personal Communications Exchange (PCX) system maintained and distributed by Alcatel.
By default, OmniPCX does not use shadowed passwords. While this is not inherently a vulnerability as OmniPCX systems are not designed for multi-user access, this problem can lead to issues such as local privilege access and elevation when combined with issues such as Bugtraq ID 4127, "Alcatel OmniPCX Default Passwords Vulnerability." If a remote user is able to gain access to the system via some unprivileged account, it is possible for the user to retrieve the encrypted password hashes and launch a brute force crack attack against them offline. This may be a Chorus OS problem, currently maintained by Sun Microsystems.