PIX Privilege Escalation Vulnerability

[email protected] 24 Jan 2008 03:41:38 -0000
Newsgroups gmane.comp.security.vulnerabilities
Message-ID <[email protected]>
Back in May of last year I started doing research on any possible securit=
y flaws that exist in the Pix/ASA Finesse operating System, versions 7.1 =
and 7.2. I discovered that a design flaw that was previously unknown in F=
inesse will allow a level 0 user to escalate their privilege to level 15.=
 I believe the vulnerability may originate in the local authentication se=
rvice, thus not being possible to exploit when Radius and TACACS is imple=
mented. Implementing AAA in any other way that keeps the passwords locall=
y defined seems to have no affect on the vulnerability. I have been able =
to repeatedly bypass the privilege-exec login both locally, through the c=
onsole and remotely, through a telnet connection. After many attempts I h=
ave found that the SSH service does not seem to suffer from the vulnerabi=
lity. =0D
	I am now going to go over the simplicity of the exploit and I will be re=
leasing a white paper hopefully sooner than later on the specifics of the=
 underlying cause. Once a user has logged on to the user-exec (level0) of=
 the device they will then be able to proceed with the <enable> command w=
hich should give you a login prompt. At this prompt if you move your curs=
or forward with a space or character(it doesn't matter if there are more =
then one), and then proceed to delete any spaces or characters, by holdin=
g down the backspace a second after deleting the last character it should=
 immediately drop you into level 15 privilege-exec mode. This attack was =
originally performed on a PIX 515E running version 7.2 of Finesse. I will=
 be posting all updates regarding this exploit as they come, and I apolog=
ize for it taking so long to release this information.=0D
=0D
Terry B Bunn=0D
LunarTEkINT Labs =0D
=0D