IBM GCM16 / GCM32 Global Console Manager KVM Switch Firmware Version < 1.20.0.22575 Remote Code Execution

high Nessus Plugin ID 77002

Synopsis

The web interface running on the remote host is affected by a remote code execution vulnerability.

Description

According to its self-reported version, the remote host is an IBM Global Console Manager KVM switch with a firmware version prior to 1.20.0.22575. It is, therefore, affected by a remote code execution vulnerability that could allow an authenticated attacker to execute commands as root via the 'ping.php' script's 'count' and 'size' parameters.

Solution

Upgrade to firmware version 1.20.0.22575 or later.

See Also

http://www.nessus.org/u?1bdd4878

Plugin Details

Severity: High

ID: 77002

File Name: ibm_gcm_kvm_MIGR-5093509.nasl

Version: 1.2

Type: remote

Family: Misc.

Published: 8/5/2014

Updated: 7/12/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/h:ibm:avocent_1754_kvm, cpe:/o:ibm:global_console_manager_16_firmware, cpe:/o:ibm:global_console_manager_32_firmware

Required KB Items: Host/IBM/GCM/Version, Host/IBM/GCM/Model

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/23/2014

Vulnerability Publication Date: 8/15/2013

Reference Information

CVE: CVE-2013-0526

BID: 61816