CVE-2005-2136

CVSS V2 Medium 4.6 CVSS V3 None
Description
Raritan Dominion SX (DSX) Console Servers DSX16, DSX32, DSX4, DSX8, and DSXA-48 set (1) world-readable permissions for /etc/shadow and (2) world-writable permissions for /bin/busybox, which allows local users to obtain hashed passwords or execute arbitrary code as other users.
Overview
  • CVE ID
  • CVE-2005-2136
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2005-07-05T04:00:00
  • Last Modified Date
  • 2023-04-25T17:27:31
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:h:raritan:dominion:sx4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:raritan:dominion:sx8:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:raritan:dominion:sx16:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:raritan:dominion:sx32:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:raritan:dominion:sx32_2.4.6_firmware:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:raritan:dominion:sxa-48:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:L/AC:L/Au:N/C:P/I:P/A:P
  • Access Vector
  • LOCAL
  • Access Compatibility
  • LOW
  • Authentication
  • NONE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • PARTIAL
  • Base Score
  • 4.6
  • Severity
  • MEDIUM
  • Exploitability Score
  • 3.9
  • Impact Score
  • 6.4
References
Reference URL Reference Tags
http://seclists.org/lists/bugtraq/2005/Jun/0251.html Exploit Patch Vendor Advisory
http://www.securityfocus.com/bid/14084
http://secunia.com/advisories/15853 Patch Vendor Advisory
History
Created Old Value New Value Data Type Notes
2022-05-10 11:27:31 Added to TrackCVE
2023-04-25 17:37:09 2023-04-25T17:27:31 CVE Modified Date updated
2023-04-25 17:37:09 Weakness Enumeration update