IBM 1754 GCM16 and GCM32 Global Console Managers Multiple Command Execution Vulnerabilities
BID:61816
Info
IBM 1754 GCM16 and GCM32 Global Console Managers Multiple Command Execution Vulnerabilities
| Bugtraq ID: | 61816 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-0526 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 16 2013 12:00AM |
| Updated: | Aug 16 2013 12:00AM |
| Credit: | Alejandro Alvarez Bravo |
| Vulnerable: |
IBM 1754 GCM32 Global Console Manager 1.18.0.22011 IBM 1754 GCM16 Global Console Manager 1.18.0.22011 |
| Not Vulnerable: |
IBM 1754 GCM32 Global Console Manager 1.20.0.22575 IBM 1754 GCM16 Global Console Manager 1.20.0.22575 |
Discussion
IBM 1754 GCM16 and GCM32 Global Console Managers Multiple Command Execution Vulnerabilities
IBM 1754 GCM16 and GCM32 Global Console Managers are prone to multiple command-execution vulnerabilities because they fail to sanitize user-supplied input.
Successful exploit of these issues may allow an attacker to execute arbitrary commands with the privileges of the root user.
The following versions are vulnerable:
IBM 1754 GCM16 Global Console Manager 1.18.0.22011 and prior
IBM 1754 GCM32 Global Console Manager 1.18.0.22011 and prior
IBM 1754 GCM16 and GCM32 Global Console Managers are prone to multiple command-execution vulnerabilities because they fail to sanitize user-supplied input.
Successful exploit of these issues may allow an attacker to execute arbitrary commands with the privileges of the root user.
The following versions are vulnerable:
IBM 1754 GCM16 Global Console Manager 1.18.0.22011 and prior
IBM 1754 GCM32 Global Console Manager 1.18.0.22011 and prior
Exploit / POC
IBM 1754 GCM16 and GCM32 Global Console Managers Multiple Command Execution Vulnerabilities
The following exploit is available:
The following exploit is available:
Solution / Fix
IBM 1754 GCM16 and GCM32 Global Console Managers Multiple Command Execution Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.