PIX Privilege Escalation Vulnerability
[email protected] 24 Jan 2008 03:41:38 -0000
| Newsgroups | gmane.comp.security.vulnerabilities |
|---|---|
| Message-ID | <[email protected]> |
Back in May of last year I started doing research on any possible securit= y flaws that exist in the Pix/ASA Finesse operating System, versions 7.1 = and 7.2. I discovered that a design flaw that was previously unknown in F= inesse will allow a level 0 user to escalate their privilege to level 15.= I believe the vulnerability may originate in the local authentication se= rvice, thus not being possible to exploit when Radius and TACACS is imple= mented. Implementing AAA in any other way that keeps the passwords locall= y defined seems to have no affect on the vulnerability. I have been able = to repeatedly bypass the privilege-exec login both locally, through the c= onsole and remotely, through a telnet connection. After many attempts I h= ave found that the SSH service does not seem to suffer from the vulnerabi= lity. =0D I am now going to go over the simplicity of the exploit and I will be re= leasing a white paper hopefully sooner than later on the specifics of the= underlying cause. Once a user has logged on to the user-exec (level0) of= the device they will then be able to proceed with the <enable> command w= hich should give you a login prompt. At this prompt if you move your curs= or forward with a space or character(it doesn't matter if there are more = then one), and then proceed to delete any spaces or characters, by holdin= g down the backspace a second after deleting the last character it should= immediately drop you into level 15 privilege-exec mode. This attack was = originally performed on a PIX 515E running version 7.2 of Finesse. I will= be posting all updates regarding this exploit as they come, and I apolog= ize for it taking so long to release this information.=0D =0D Terry B Bunn=0D LunarTEkINT Labs =0D =0D