Multiple Infoblox Network Automation Products Local Security Bypass Vulnerability
BID:68473
Info
Multiple Infoblox Network Automation Products Local Security Bypass Vulnerability
| Bugtraq ID: | 68473 |
| Class: | Design Error |
| CVE: |
CVE-2014-3419 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 09 2014 12:00AM |
| Updated: | Jul 09 2014 12:00AM |
| Credit: | Nate Kettlewell of Depth Security |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Multiple Infoblox Network Automation Products Local Security Bypass Vulnerability
Multiple Infoblox Network Automation Products including NetMRI, Switch Port Manager, Automation Change Manager and Security Device Controller are prone to a local security-bypass vulnerability.
Local attackers may exploit this issue to bypass certain security restrictions and perform unauthorized actions.
Multiple Infoblox Network Automation Products including NetMRI, Switch Port Manager, Automation Change Manager and Security Device Controller are prone to a local security-bypass vulnerability.
Local attackers may exploit this issue to bypass certain security restrictions and perform unauthorized actions.
Exploit / POC
Multiple Infoblox Network Automation Products Local Security Bypass Vulnerability
The researcher who has discovered this issue has given a proof-of-concept code. Please see the references for more information.
The researcher who has discovered this issue has given a proof-of-concept code. Please see the references for more information.
Solution / Fix
Multiple Infoblox Network Automation Products Local Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple Infoblox Network Automation Products Local Security Bypass Vulnerability
References:
References:
- Automation Change Manager Homepage (Infoblox)
- Infoblox Security Device Controller Homepage (Infoblox)
- NetMRI Homepage (Infoblox)
- OS Command Injection in Infoblox NetMRI Products - CVE-2014-3418 + CVE-2014-3419 (DepthSecurity)
- Switch Port Manager Homepage (Infoblox)
- Weak Local Database Credentials in Infoblox Network Automation (SecLists.Org)