search menu icon-carat-right cmu-wordmark

CERT Coordination Center

IRISconsole allows login to the "iceadmin" account with incorrect password

Vulnerability Note VU#498707

Original Release Date: 2003-08-18 | Last Revised: 2003-08-18

Overview

SGI IRIS console contains a vulnerability which may allow a local attacker to gain elevated privileges.

Description

SGI describes IRISconsole as a "central control point that manages and monitors servers and logs their activity." A vulnerability in IRISconsole may allow a local attacker to login to the icadmin account. Doing so may allow the attacker to gain elevated privileges. For further technical information, please see SGI Security Advisory 20020406-01-P.

Impact

A local attacker may be able to elevate their privileges.

Solution

Apply a vendor patch.

Vendor Information

498707
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to SGI for publishing information about this vulnerability.

This document was written by Ian A. Finlay.

Other Information

CVE IDs: CVE-2002-0171
Severity Metric: 3.38
Date Public: 2002-04-24
Date First Published: 2003-08-18
Date Last Updated: 2003-08-18 18:21 UTC
Document Revision: 9

Sponsored by CISA.