APC Switched Rack PDU unspecified security bypass
| apcpdu-unspecified-security-bypass (38783) |
Description:
An unspecified error in APC Switched Rack PDUs (Power Distribution Units) could allow a remote attacker to bypass security restrictions. An attacker could exploit this vulnerability using unknown attack vectors and gain unauthorized access to the system to control the distribution of power to the computer equipment.
Platforms Affected:
- APC, OAS 3.5.6
- APC, Rack Power Distribution Unit 3.5.5
Remedy:
No remedy available as of July 13, 2008.
Consequences:
Bypass Security
References:
- BugTraq Mailing List, Thu Nov 29 2007 - 08:41:38 CST, APC Management Vulnerability at http://archives.neohapsis.com/archives/bugtraq/2007-11/0416.html.
- BID-26636: APC Switched Rack PDU Authentication Bypass Vulnerability
- CVE-2007-6226: The American Power Conversion (APC) AP7932 0u 30amp Switched Rack Power Distribution Unit (PDU), with rpdu 3.5.5 and aos 3.5.6, allows remote attackers to bypass authentication and obtain login access by making a login attempt while a different client is logged in, and then resubmitting the login attempt once the other client exits.
- SECTRACK ID: 1019018: APC Switched Rack Power Distribution Units Grant Limited Access to Remote Users
Reported:
Nov 29, 2007
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
