Vulnerability Name: | CVE-2010-0833 (CCN-60773) | ||||||||
Assigned: | 2010-07-26 | ||||||||
Published: | 2010-07-26 | ||||||||
Updated: | 2018-10-10 | ||||||||
Summary: | The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 before build 8046, and 6.0 before build 8234, as used in HP StorageWorks X9000 Network Storage Systems and possibly other products, uses "SetPassword logic" when running as part of a root service, which allows remote attackers to bypass authentication for a Likewise Security Authority (lsassd) account whose password is marked as expired. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-287 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-0833 Source: CCN Type: HP Security Bulletin HPSBST02630 SSRT1000385 HP StorageWorks X9000 Network Storage Systems, Remote Unauthenticated Access Source: HP Type: UNKNOWN SSRT1000385 Source: CCN Type: SA40725 Likewise Open / Likewise-CIFS pam_lsass Logic Error Security Bypass Source: SECUNIA Type: Vendor Advisory 40725 Source: SECUNIA Type: Vendor Advisory 40736 Source: CCN Type: SA43244 HP StorageWorks X9000 Network Storage Systems Security Bypass Vulnerability Source: SECUNIA Type: Vendor Advisory 43244 Source: CCN Type: LWSA-2010-001 Likewise Open 5.4 & 6.0 security announcement Source: CONFIRM Type: Patch, Vendor Advisory http://www.likewise.com/community/index.php/forums/viewthread/772/ Source: CCN Type: OSVDB ID: 66806 Likewise Open / Likewise-CIFS pam_lsass Library SetPassword Logic Expired Password Authentication Bypass Source: BUGTRAQ Type: UNKNOWN 20100726 [LWSA-2010-001] Likewise Open 5.4 & 6.0 Source: CCN Type: BID-41969 Likewise Open 'pam_lsass' Library Local Security Bypass Vulnerability Source: SECTRACK Type: UNKNOWN 1025031 Source: UBUNTU Type: UNKNOWN USN-964-1 Source: VUPEN Type: Vendor Advisory ADV-2010-1913 Source: VUPEN Type: Vendor Advisory ADV-2011-0312 Source: XF Type: UNKNOWN lo-cifs-pamlsass-security-bypass(60773) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |