积极预防 及时发现
快速响应 力保恢复
OmniPCX是企业级的Personal Communications Exchange (PCX)...
发布时间:2002-03-11 信息来源:管理员

CNCVE编号:CNCVE-20020041 CVE编号: 安全级别:高 漏洞中文描述: OmniPCX是企业级的Personal Communications Exchange (PCX)系统,由Alcatel负责维护开发。缺省情况下,OmniPCX系统未对口令采用shadow技术。结果任一非特权用户都可以获取/etc/passwd中的口令密文,并采用暴力法破解它们。 漏洞英文描述: OmniPCX is an enterprise-level Personal Communications Exchange (PCX) system maintained and distributed by Alcatel. By default, OmniPCX does not use shadowed passwords. While this is not inherently a vulnerability as OmniPCX systems are not designed for multi-user access, this problem can lead to issues such as local privilege access and elevation when combined with issues such as Bugtraq ID 4127, "Alcatel OmniPCX Default Passwords Vulnerability." If a remote user is able to gain access to the system via some unprivileged account, it is possible for the user to retrieve the encrypted password hashes and launch a brute force crack attack against them offline. This may be a Chorus OS problem, currently maintained by Sun Microsystems. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0188.html http://www.ind.alcatel.com/omnipcx/index.cfm?cnt=index 系统类型:其他 漏洞类型:设计错误