Improper file permission in iDRAC Service Module - CVE-2018-11053

 

Improper file permission in iDRAC Service Module - CVE-2018-11053

Published: August 27, 2018 / Updated: February 21, 2019


Vulnerability identifier: #VU14572
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11053
CWE-ID: CWE-276
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to the software changes the default file permission of the hosts file of the host operating system (/etc/hosts) to world writable. A remote attacker can modify the host file and potentially redirect traffic from the intended destination to sites hosting malicious or unwanted content.


Affected software

iDRAC Service Module

How to mitigate CVE-2018-11053

Install update from vendor's website.


External References

Related Security Bulletins