Vulnerability Name:

CVE-2004-1345 (CCN-16463)

Assigned:2004-06-18
Published:2004-06-18
Updated:2017-10-11
Summary:Unknown vulnerability in Sun StorEdge Enterprise Storage Manager (ESM) 2.1 for Solaris 8 and Solaris 9 allows local users with the "ESMUser" role to gain root access.
CVSS v3 Severity:3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
2.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2004-1345

Source: CCN
Type: SA11935
Sun StorEdge ESM Unspecified Privilege Escalation Vulnerability

Source: SECUNIA
Type: Patch, Vendor Advisory
11935

Source: CCN
Type: Sun Alert ID: 57581
Systems With Enterprise Storage Manager 2.1 Installed May Allow an Unprivileged Local User to Gain Root Acess

Source: SUNALERT
Type: Patch, Vendor Advisory
57581

Source: CCN
Type: CIAC Information Bulletin O-166
Sun StorEdge Enterprise Storage Manager (ESM) 2.1 Vulnerability

Source: CIAC
Type: Patch, Vendor Advisory
O-166

Source: CCN
Type: US-CERT VU#976470
Sun Enterprise Storage Manager may allow an unprivileged local user to gain root access

Source: CERT-VN
Type: Patch, Third Party Advisory, US Government Resource
VU#976470

Source: BID
Type: Patch, Vendor Advisory
10580

Source: CCN
Type: BID-10580
Sun Enterprise Storage Manager Local Unspecified Privilege Escalation Vulnerability

Source: XF
Type: UNKNOWN
esm-esmuser-gain-privileges(16463)

Source: XF
Type: UNKNOWN
esm-esmuser-gain-privileges(16463)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:1707

Vulnerable Configuration:Configuration 1:
  • cpe:/h:sun:storedge_3310_scsi_array:*:*:*:*:*:*:*:*
  • OR cpe:/h:sun:storedge_3510_fc_array:*:*:*:*:*:*:*:*
  • AND
  • cpe:/a:sun:enterprise_storage_manager:2.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:internet_explorer:6.0.2900.2180:*:*:*:*:*:*:*
  • AND
  • cpe:/o:microsoft:windows:xp:sp2:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:1707
    V
    Enterprise Storage Manager 2.1 SAN Manager management station patch
    2009-07-13
    BACK
    sun storedge 3310 scsi array *
    sun storedge 3510 fc array *
    sun enterprise storage manager 2.1
    microsoft ie 6.0.2900.2180
    microsoft windows xp sp2