Rapid7 Vulnerability & Exploit Database

HP-UX: CVE-2004-0952: Ignite-UX, Remote Unauthorized Access

Back to Search

HP-UX: CVE-2004-0952: Ignite-UX, Remote Unauthorized Access

Severity
6
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:P)
Published
12/31/2004
Created
07/25/2018
Added
08/11/2017
Modified
09/12/2017

Description

HP-UX B.11.00 through B.11.23, when running Ignite-UX and using the add_new_client command, causes the TFTP server to set world-writable permissions on part of the directory tree, which allows remote attackers to modify data or cause disk consumption.

Solution(s)

  • hpux-update-ignite-ux-boot-common-ia
  • hpux-update-ignite-ux-boot-common-pa
  • hpux-update-ignite-ux-boot-krn-11-00
  • hpux-update-ignite-ux-boot-krn-11-11
  • hpux-update-ignite-ux-boot-krn-11-22
  • hpux-update-ignite-ux-boot-krn-11-23
  • hpux-update-ignite-ux-boot-services
  • hpux-update-ignite-ux-cfg-file-11-22
  • hpux-update-ignite-ux-file-srv-11-00
  • hpux-update-ignite-ux-file-srv-11-11
  • hpux-update-ignite-ux-file-srv-11-23
  • hpux-update-ignite-ux-filesrv-1122ia
  • hpux-update-ignite-ux-ignite
  • hpux-update-ignite-ux-mgmt-tools
  • hpux-update-ignite-ux-obam-run
  • hpux-update-ignite-ux-recovery

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;