vendor:
vAPV and vxAG
by:
xistence
7.5
CVSS
HIGH
Default Hardcoded Private SSH Key or Default Hardcoded Login and Password
CWE
Product Name: vAPV and vxAG
Affected Version From: vAPV 8.3.2.17 and vxAG 9.2.0.34
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: unix
2014
Array Networks vAPV and vxAG Private Key Privelege Escalation Code Execution
This module exploits a default hardcoded private SSH key or default hardcoded login and password in the vAPV 8.3.2.17 and vxAG 9.2.0.34 appliances made by Array Networks. After logged in as the unprivileged user, it's possible to modify the world writable file /ca/bin/monitor.sh with our arbitrary code. Execution of the arbitrary code is possible by using the backend tool, running setuid, to turn the debug monitoring on. This makes it possible to trigger our payload with root privileges.
Mitigation:
Update to a version that does not have this vulnerability