exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

n.runs-SA-2008.009.txt

n.runs-SA-2008.009.txt
Posted Oct 27, 2008
Authored by Jan Rossmann, Jan Wagner | Site nruns.com

The Network Shutdown Module version 3.10 from Eaton MGE office protection systems suffers from authentication bypass and remote code execution vulnerabilities.

tags | advisory, remote, vulnerability, code execution
SHA-256 | d54c89c3c99024d0e1e9654f37ed1b75ef5c1b7f276771d249be6e1057c18576

n.runs-SA-2008.009.txt

Change Mirror Download
n.runs AG
http://www.nruns.com/ security(at)nruns.com
n.runs-SA-2008.009 27-October-2008
____________________________________________________________________________

Vendor: Eaton MGE office protection systems
Affected Products: Network Shutdown Module version 3.10
Vulnerability: authentication bypass vulnerability and remote code
execution
Risk: High
____________________________________________________________________________

Vendor communication:


2008/08/13 initial notification of EATON MGE Office Protection
Systems (MGEOPS)
2008/08/20 second notification of MGEOPS
2008/08/20 MGEOPS confirmation of receiving information
2008/08/25 receiving patch proposal from MGEOPS
2008/08/29 confirmation of proper patch, asking of release date
2008/09/02 awaiting feedback regarding release date of the patch
2008/09/18 patch and new version undergoing QA process of MGEOPS
still no release date known
2008/10/07 another request regarding the release date
2008/10/21 MGEOPS informs n.runs AG about release of the new
software version
2008/10/27 n.runs AG releases this advisory
____________________________________________________________________________

Overview:
--------
EATON MGE Office Protection Systems designs and manufactures secured
power products and solutions for enterprises, small business and homes.
The Network Shutdown Module continuously wait for information from the
Management Proxy or Management Card connected to the EATON UPS and warns
administrators and users if AC power fails and proceeds with graceful
system shutdown before the end of battery backup power is reached.

Description:
--------
Remote exploitation of an authentication bypass vulnerability could
allow an attacker to execute arbitrary code.

In detail, the following flaw was determined:

- Custom actions can be added to the MGE frontend without authentication
required (pane_actionbutton.php)
- Actions can be executed (tested) without authentication required
(exec_action.php)


Impact:
--------
This problem can lead to a remote file execution vulnerability. It can
allow an attacker to add and execute custom actions. The commands to be
executed are included within the added action.

The vulnerability is present in MGE Network Shutdown Module software
versions prior 3.10 build 13.

Solution
--------
EATON MGE Office Protection Systems has issued an update to correct this
vulnerability. A new version of the software (version 3.20) can be found at:
http://download.mgeops.com/explore/eng/network/net_sol.htm
________________________________________________________________________

Credits:
Bug found by Jan Rossmann and Jan Wagner of n.runs AG.
________________________________________________________________________

References:
This Advisory and Upcoming Advisories:
http://www.nruns.com/security_advisory.php

Subscribe to the n.runs newsletter by signing up to:
http://www.nruns.com/newsletter_en.php
________________________________________________________________________

About n.runs:
n.runs AG is a vendor-independent consulting company specialising in the
areas of: IT Infrastructure, IT Security and IT Business Consulting. In
2007, n.runs expanded its core business area, which until then had been
project based consulting, to include the development of high-end
security solutions.
Application Protection System - Anti Virus (aps-AV) is the first
high-end security solution that n.runs is bringing to the market.

Copyright Notice:
Unaltered electronic reproduction of this advisory is permitted. For all
other reproduction or publication, in printing or otherwise, contact
security@nruns.com for permission. Use of the advisory constitutes
acceptance for use in an "as is" condition. All warranties are excluded.
In no event shall n.runs be liable for any damages whatsoever including
direct, indirect, incidental, consequential, loss of business profits or
special damages, even if n.runs has been advised of the possibility of
such damages.

Copyright 2008 n.runs AG. All rights reserved. Terms of use apply.


Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close