Lucene search

K
cveMitreCVE-2005-2136
HistoryJul 05, 2005 - 4:00 a.m.

CVE-2005-2136

2005-07-0504:00:00
CWE-863
mitre
web.nvd.nist.gov
36
raritan
dominion
sx
dsx
console servers
cve-2005-2136
vulnerability
local users
permissions
hashed passwords
arbitrary code
nvd

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.7

Confidence

High

EPSS

0

Percentile

5.1%

Raritan Dominion SX (DSX) Console Servers DSX16, DSX32, DSX4, DSX8, and DSXA-48 set (1) world-readable permissions for /etc/shadow and (2) world-writable permissions for /bin/busybox, which allows local users to obtain hashed passwords or execute arbitrary code as other users.

Affected configurations

Nvd
Node
raritandominion_sx4_firmwareMatch-
AND
raritandominion_sx4Match-
Node
raritandominion_sx8_firmwareMatch-
AND
raritandominion_sx8Match-
Node
raritandominion_sx16_firmwareMatch-
AND
raritandominion_sx16Match-
Node
raritandominion_sx32_firmwareMatch2.4.6
AND
raritandominion_sx32Match-
Node
raritandominion_sxa-48_firmwareMatch-
AND
raritandominion_sxa-48Match-
VendorProductVersionCPE
raritandominion_sx4_firmware-cpe:2.3:o:raritan:dominion_sx4_firmware:-:*:*:*:*:*:*:*
raritandominion_sx4-cpe:2.3:h:raritan:dominion_sx4:-:*:*:*:*:*:*:*
raritandominion_sx8_firmware-cpe:2.3:o:raritan:dominion_sx8_firmware:-:*:*:*:*:*:*:*
raritandominion_sx8-cpe:2.3:h:raritan:dominion_sx8:-:*:*:*:*:*:*:*
raritandominion_sx16_firmware-cpe:2.3:o:raritan:dominion_sx16_firmware:-:*:*:*:*:*:*:*
raritandominion_sx16-cpe:2.3:h:raritan:dominion_sx16:-:*:*:*:*:*:*:*
raritandominion_sx32_firmware2.4.6cpe:2.3:o:raritan:dominion_sx32_firmware:2.4.6:*:*:*:*:*:*:*
raritandominion_sx32-cpe:2.3:h:raritan:dominion_sx32:-:*:*:*:*:*:*:*
raritandominion_sxa-48_firmware-cpe:2.3:o:raritan:dominion_sxa-48_firmware:-:*:*:*:*:*:*:*
raritandominion_sxa-48-cpe:2.3:h:raritan:dominion_sxa-48:-:*:*:*:*:*:*:*

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.7

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2005-2136