VxWorks Insecure Password Hashing Vulnerability
BID:42114
Info
VxWorks Insecure Password Hashing Vulnerability
| Bugtraq ID: | 42114 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2010 12:00AM |
| Updated: | Aug 05 2010 07:46PM |
| Credit: | HD Moore |
| Vulnerable: |
Wind River Systems VxWorks 0 |
| Not Vulnerable: | |
Discussion
VxWorks Insecure Password Hashing Vulnerability
VxWorks is prone to a security vulnerability due to an insecure-hashing algorithm.
Successful exploits will allow remote attackers to perform brute-force attacks and obtain the password used for FTP and Telnet services.
The issue affects multiple products from multiple vendors that ship with the VxWorks operating system.
NOTE: This document previously covered two vulnerabilities in VxWorks. The remote security-bypass issue has been moved to BID 42158 (VxWorks Debugging Service Security-Bypass Vulnerability) to allow for better documentation of both issues.
VxWorks is prone to a security vulnerability due to an insecure-hashing algorithm.
Successful exploits will allow remote attackers to perform brute-force attacks and obtain the password used for FTP and Telnet services.
The issue affects multiple products from multiple vendors that ship with the VxWorks operating system.
NOTE: This document previously covered two vulnerabilities in VxWorks. The remote security-bypass issue has been moved to BID 42158 (VxWorks Debugging Service Security-Bypass Vulnerability) to allow for better documentation of both issues.
Exploit / POC
VxWorks Insecure Password Hashing Vulnerability
Attackers can exploit this issue using readily available tools.
A Metasploit exploit module has been developed for this issue; reports indicate that it will be publicly available in September 2010.
Attackers can exploit this issue using readily available tools.
A Metasploit exploit module has been developed for this issue; reports indicate that it will be publicly available in September 2010.
Solution / Fix
VxWorks Insecure Password Hashing Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
References
VxWorks Insecure Password Hashing Vulnerability
References:
References:
- Shiny Old VxWorks Vulnerabilities (Metasploit)
- Wind River Homepage (Wind River)
- [R7-0035] VxWorks Authentication Library Weak Password Hashing (HD Moore
) - Re: [R7-0035] VxWorks Authentication Library Weak Password Hashing (Solar Designer
) - Vulnerability Note VU#840249 Wind River Systems VxWorks weak default hashing alg (US-CERT)