Aruba Mobility Controller guest account privilege escalation
| aruba-guestaccount-privilege-escalation (32461) |
Description:
Aruba Mobility Controller could allow a remote attacker to gain elevated privileges, caused by a vulnerability regarding the implementation of the default guest account. A remote attacker with knowledge of the guest account name could exploit this vulnerability to gain unauthorized administrative access to the Mobility Controller.
*CVSS:
| Base Score: | 8 |
| Access Vector: | Remote |
| Access Complexity: | High |
| Authentication: | Not Required |
| Confidentiality Impact: | Complete |
| Integrity Impact: | Complete |
| Availability Impact: | Complete |
| Temporal Score: | 5.9 |
| Exploitability: | Unproven |
| Remediation Level: | Official-Fix |
| Report Confidence: | Confirmed |
Consequences:
Gain Access
Remedy:
Aruba Networks customers are advised to upgrade to the latest patched version of the firmware available from the Aruba Networks Web site. See References.
References:
- Aruba Networks Web site: Aruba Mobility Controllers.
- Full-Disclosure Mailing List, Mon Feb 12 2007 - 18:19:05 CST: Aruba Networks - Unauthorized Administrative and WLAN Access through Guest Account.
- BID-22538: Aruba Mobility Controller Multiple Vulnerabilities
- CVE-2007-0932: The (1) Aruba Mobility Controllers 200, 600, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 do not properly implement authentication and privilege assignment for the guest account, which allows remote attackers to access administrative interfaces or the WLAN.
- SA24144: Aruba Mobility Controller Two Vulnerabilities
- US-CERT VU#613833: Aruba Mobility Controller vulnerable to privilege escalation
Platforms Affected:
- Alcatel-Lucent OmniAccess Wireless 43xx
- Alcatel-Lucent OmniAccess Wireless 6000
- Aruba Networks Mobility Controller 200 2.0 and later
- Aruba Networks Mobility Controller 2400 2.0 and later
- Aruba Networks Mobility Controller 6000 2.0 and later
- Aruba Networks Mobility Controller 800 2.0 and later
Reported:
Feb 13, 2007
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
* According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall IBM be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
