Lucene search

K
nessusThis script is Copyright (C) 2010-2021 and is owned by Tenable, Inc. or an Affiliate thereof.HPUX_PHSS_40230.NASL
HistoryFeb 08, 2010 - 12:00 a.m.

HP-UX PHSS_40230 : HP Enterprise Cluster Master Toolkit (ECMT) running on HP-UX, Local Unauthorized Access (HPSBUX02464 SSRT090210 rev.1)

2010-02-0800:00:00
This script is Copyright (C) 2010-2021 and is owned by Tenable, Inc. or an Affiliate thereof.
www.tenable.com
18

CVSS2

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

NONE

AV:L/AC:L/Au:S/C:C/I:C/A:N

EPSS

0

Percentile

5.1%

s700_800 11.31 ECMT B.05.00 patch :

A potential security vulnerability has been identified on HP Enterprise Cluster Master Toolkit (ECMT) version B.05.00 running on HP-UX. This vulnerability could be exploited by local users to gain unauthorized access.

#%NASL_MIN_LEVEL 70300
#
# (C) Tenable Network Security, Inc.
#
# The descriptive text and patch checks in this plugin were 
# extracted from HP patch PHSS_40230. The text itself is
# copyright (C) Hewlett-Packard Development Company, L.P.
#

include('deprecated_nasl_level.inc');
include('compat.inc');

if (description)
{
  script_id(44405);
  script_version("1.13");
  script_set_attribute(attribute:"plugin_modification_date", value:"2021/01/11");

  script_cve_id("CVE-2009-4184");
  script_xref(name:"HP", value:"emr_na-c01894850");
  script_xref(name:"HP", value:"HPSBUX02464");
  script_xref(name:"HP", value:"SSRT090210");

  script_name(english:"HP-UX PHSS_40230 : HP Enterprise Cluster Master Toolkit (ECMT) running on HP-UX, Local Unauthorized Access (HPSBUX02464 SSRT090210 rev.1)");
  script_summary(english:"Checks for the patch in the swlist output");

  script_set_attribute(
    attribute:"synopsis", 
    value:"The remote HP-UX host is missing a security-related patch."
  );
  script_set_attribute(
    attribute:"description", 
    value:
"s700_800 11.31 ECMT B.05.00 patch : 

A potential security vulnerability has been identified on HP
Enterprise Cluster Master Toolkit (ECMT) version B.05.00 running on
HP-UX. This vulnerability could be exploited by local users to gain
unauthorized access."
  );
  # http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01894850
  script_set_attribute(
    attribute:"see_also",
    value:"http://www.nessus.org/u?2836dd8b"
  );
  script_set_attribute(
    attribute:"solution", 
    value:"Install patch PHSS_40230 or subsequent."
  );
  script_set_cvss_base_vector("CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:N");

  script_set_attribute(attribute:"plugin_type", value:"local");
  script_set_attribute(attribute:"cpe", value:"cpe:/o:hp:hp-ux");

  script_set_attribute(attribute:"vuln_publication_date", value:"2010/02/03");
  script_set_attribute(attribute:"patch_publication_date", value:"2010/02/02");
  script_set_attribute(attribute:"plugin_publication_date", value:"2010/02/08");
  script_set_attribute(attribute:"generated_plugin", value:"current");
  script_end_attributes();

  script_category(ACT_GATHER_INFO);
  script_copyright(english:"This script is Copyright (C) 2010-2021 and is owned by Tenable, Inc. or an Affiliate thereof.");
  script_family(english:"HP-UX Local Security Checks");

  script_dependencies("ssh_get_info.nasl");
  script_require_keys("Host/local_checks_enabled", "Host/HP-UX/version", "Host/HP-UX/swlist");

  exit(0);
}


include("audit.inc");
include("global_settings.inc");
include("hpux.inc");


if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED);
if (!get_kb_item("Host/HP-UX/version")) audit(AUDIT_OS_NOT, "HP-UX");
if (!get_kb_item("Host/HP-UX/swlist")) audit(AUDIT_PACKAGE_LIST_MISSING);

if (!hpux_check_ctx(ctx:"11.31"))
{
  exit(0, "The host is not affected since PHSS_40230 applies to a different OS release.");
}

patches = make_list("PHSS_40230", "PHSS_40792", "PHSS_40987", "PHSS_41316");
foreach patch (patches)
{
  if (hpux_installed(app:patch))
  {
    exit(0, "The host is not affected because patch "+patch+" is installed.");
  }
}


flag = 0;
if (hpux_check_patch(app:"SG-Oracle-Tool.CM-ORACLE", version:"B.05.00")) flag++;
if (hpux_check_patch(app:"SG-Sybase-Tool.CM-SYBASE", version:"B.05.00")) flag++;


if (flag)
{
  if (report_verbosity > 0) security_warning(port:0, extra:hpux_report_get());
  else security_warning(0);
  exit(0);
}
else audit(AUDIT_HOST_NOT, "affected");

CVSS2

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

NONE

AV:L/AC:L/Au:S/C:C/I:C/A:N

EPSS

0

Percentile

5.1%