Vulnerability Name:

CVE-2007-5717 (CCN-38149)

Assigned:2007-10-29
Published:2007-10-29
Updated:2017-07-29
Summary:Unspecified vulnerability in Sun Fire X2100 M2 and X2200 M2 Embedded Lights Out Manager (ELOM) on x86 before firmware 2.70 allows remote attackers to execute arbitrary commands as root on the Service Processor (SP) via unspecified vectors, a different vulnerability than CVE-2007-5170.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
9.3 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2007-5717

Source: OSVDB
Type: UNKNOWN
40835

Source: CCN
Type: SA27416
Sun Fire X2100/X2200 Embedded Lights Out Manager Command Execution

Source: SECUNIA
Type: UNKNOWN
27416

Source: CCN
Type: SECTRACK ID: 1018869
Sun Fire Server Embedded Lights Out Manager Software Lets Remote Users Execute Arbitrary Commands

Source: CCN
Type: Sun Alert ID: 103127
Sun Fire X2100/X2200 M2 Servers ELOM Software is Vulnerable to Arbitrary Command Execution

Source: SUNALERT
Type: Patch
103127

Source: SUNALERT
Type: UNKNOWN
200667

Source: CCN
Type: OSVDB ID: 40835
Sun Fire X2100/X2200 Embedded Lights Out Manager (ELOM) Unspecified Remote Command Execution

Source: CCN
Type: OSVDB ID: 52576
Sun Fire X2100 / X2200 Embedded Lights Out Manager (ELOM) Unspecified Remote Privilege Escalation (6633175)

Source: CCN
Type: OSVDB ID: 52577
Sun Fire X2100 / X2200 Embedded Lights Out Manager (ELOM) Unspecified Remote Privilege Escalation (6648082)

Source: BID
Type: UNKNOWN
26250

Source: CCN
Type: BID-26250
Sun Fire X2100 M2 And X2200 M2 ELOM Unspecified Remote Arbitrary Command Execution Vulnerability

Source: SECTRACK
Type: UNKNOWN
1018869

Source: VUPEN
Type: UNKNOWN
ADV-2007-3652

Source: XF
Type: UNKNOWN
sunfire-elom-command-execution(38149)

Source: XF
Type: UNKNOWN
sunfire-elom-command-execution(38149)

Vulnerable Configuration:Configuration 1:
  • cpe:/h:sun:sun_fire:x2100m2:firmware_2.70:*:*:*:*:*:*
  • OR cpe:/h:sun:sun_fire:x2200m2:firmware_2.70:*:*:*:*:*:*
  • AND
  • cpe:/a:sun:embedded_lights_out_manager:*:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:sun:embedded_lights_out_manager:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sun sun fire x2100m2 firmware_2.70
    sun sun fire x2200m2 firmware_2.70
    sun embedded lights out manager *
    sun embedded lights out manager *