APC Switched Rack PDU unspecified security bypass

apcpdu-unspecified-security-bypass (38783) The risk level is classified as MediumMedium Risk

Description:

An unspecified error in APC Switched Rack PDUs (Power Distribution Units) could allow a remote attacker to bypass security restrictions. An attacker could exploit this vulnerability using unknown attack vectors and gain unauthorized access to the system to control the distribution of power to the computer equipment.

Platforms Affected:

  • APC, OAS 3.5.6
  • APC, Rack Power Distribution Unit 3.5.5

Remedy:

No remedy available as of July 13, 2008.

Consequences:

Bypass Security

References:

  • BugTraq Mailing List, Thu Nov 29 2007 - 08:41:38 CST, APC Management Vulnerability at http://archives.neohapsis.com/archives/bugtraq/2007-11/0416.html.
  • BID-26636: APC Switched Rack PDU Authentication Bypass Vulnerability
  • CVE-2007-6226: The American Power Conversion (APC) AP7932 0u 30amp Switched Rack Power Distribution Unit (PDU), with rpdu 3.5.5 and aos 3.5.6, allows remote attackers to bypass authentication and obtain login access by making a login attempt while a different client is logged in, and then resubmitting the login attempt once the other client exits.
  • SECTRACK ID: 1019018: APC Switched Rack Power Distribution Units Grant Limited Access to Remote Users

Reported:

Nov 29, 2007

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.

For corrections or additions please email xforce@iss.net

Return to the main page