Castle Rock Computing SNMPc v5/v6 Unauthorized Remote Privileged Access Vulnerability
BID:8484
Info
Castle Rock Computing SNMPc v5/v6 Unauthorized Remote Privileged Access Vulnerability
| Bugtraq ID: | 8484 |
| Class: | Design Error |
| CVE: |
CVE-2003-0745 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 25 2003 12:00AM |
| Updated: | Mar 19 2015 09:34AM |
| Credit: | The discovery of this vulnerability has been credited to "Alexander V. Nickolenko" <[email protected]>. |
| Vulnerable: |
Castlerock SNMPc 6.0.8 Castlerock SNMPc 6.0.5 Castlerock SNMPc 6.0 Castlerock SNMPc 5.1 |
| Not Vulnerable: |
Castlerock SNMPc 5.1.9 |
Discussion
Castle Rock Computing SNMPc v5/v6 Unauthorized Remote Privileged Access Vulnerability
A vulnerability in the authentication mechanism used by SNMPc has been discovered, potentially allowing for unauthorized remote access. The problem lies in the design of the mechanism, specifically the fact that all authentication routines are carried out within the client program. As such, an attacker may be capable of influencing the results of authentication by modifying a client program or reversing the encrypted password transmitted by the server.
The exploitation of this issue could ultimately allow for an attacker to gain unauthorized remote console access as the Administrator user, who by default has Supervisor privileges on affected servers.
This vulnerability affects SNMPc v5 and version v6.
A vulnerability in the authentication mechanism used by SNMPc has been discovered, potentially allowing for unauthorized remote access. The problem lies in the design of the mechanism, specifically the fact that all authentication routines are carried out within the client program. As such, an attacker may be capable of influencing the results of authentication by modifying a client program or reversing the encrypted password transmitted by the server.
The exploitation of this issue could ultimately allow for an attacker to gain unauthorized remote console access as the Administrator user, who by default has Supervisor privileges on affected servers.
This vulnerability affects SNMPc v5 and version v6.
Exploit / POC
Castle Rock Computing SNMPc v5/v6 Unauthorized Remote Privileged Access Vulnerability
A proof of console exploit script has been made available "Alexander V. Nickolenko" <[email protected]>. A sample usage of this exploit is available in the attached message reference.
A proof of console exploit script has been made available "Alexander V. Nickolenko" <[email protected]>. A sample usage of this exploit is available in the attached message reference.
Solution / Fix
Castle Rock Computing SNMPc v5/v6 Unauthorized Remote Privileged Access Vulnerability
Solution:
Castle Rock Computing has created fixes to address this issue in specific 6.x releases, as well as a completely revised 5.x release which addresses this vulnerability. Users are advised to upgrade as soon as possible.
Fixes:
Castlerock SNMPc 5.1
Castlerock SNMPc 6.0.5
Castlerock SNMPc 6.0.8
Solution:
Castle Rock Computing has created fixes to address this issue in specific 6.x releases, as well as a completely revised 5.x release which addresses this vulnerability. Users are advised to upgrade as soon as possible.
Fixes:
Castlerock SNMPc 5.1
-
Castle Rock Computing snmpc519.exe
http://www.castlerock.com/download/snmpc519.exe
Castlerock SNMPc 6.0.5
-
Castle Rock Computing fix821_605.zip
http://www.castlerock.com/download/fix821_605.zip
Castlerock SNMPc 6.0.8
-
Castle Rock Computing fix821_608.zip
http://www.castlerock.com/download/fix821_608.zip
References
Castle Rock Computing SNMPc v5/v6 Unauthorized Remote Privileged Access Vulnerability
References:
References:
- Castle Rock Computing SNMPc Product Page (Castle Rock Computing)
- SNMPc v5 and v6 remote vulnerability ("Alexander V. Nickolenko"
)