vendor:
IBM Tivoli Storage Manager Express CAD Service
by:
Mati Aharoni
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: IBM Tivoli Storage Manager Express CAD Service
Affected Version From: 5.3
Affected Version To: 5.3
Patch Exists: NO
Related CWE: CVE not mentioned
CPE: a:ibm:tivoli_storage_manager_express_cad_service:5.3
Metasploit:
https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2022-23499/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2022-3643/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2022-3643/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2022-3643/, https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2022-3643/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-2-cve-2022-3643/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2022-3172/, https://www.rapid7.com/db/vulnerabilities/alma_linux-cve-2021-20325/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2021-20325/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2021-20325/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2021-20325/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2021-37698/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2021-37698/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-2-cve-2020-25686/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2020-25686/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp2-cve-2020-25686/, https://www.rapid7.com/db/vulnerabilities/alma_linux-cve-2020-25686/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp9-cve-2020-25686/, https://www.rapid7.com/db/vulnerabilities/redhat-openshift-cve-2020-25686/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp3-cve-2020-25686/, https://www.rapid7.com/db/?q=CVE+not+mentioned&type=&page=2, https://www.rapid7.com/db/?q=CVE+not+mentioned&type=&page=3, https://www.rapid7.com/db/?q=CVE+not+mentioned&type=&page=2
Platforms Tested: Windows 2003 server SP0
Unknown
IBM Tivoli Storage Manager Express CAD Service Buffer Overflow (5.3)
This exploit allows an attacker to execute arbitrary code on a target system by sending a specially crafted buffer to the IBM Tivoli Storage Manager Express CAD Service. The buffer overflow vulnerability exists in version 5.3 of the software. The exploit code provided in the script connects to a target host and sends the malicious buffer. If successful, it opens a bindshell on port 4444 for the attacker to gain remote access to the system. The script was tested on a Windows 2003 server SP0.
Mitigation:
Upgrade to a patched version of IBM Tivoli Storage Manager Express CAD Service.