Secunia Logo
 
Fujitsu PRIMERGY BX300 Web Interface Authentication Bypass
Secunia Advisory: SA25943
Release Date: 2007-07-05
Popularity: 6,368 views

Critical:
Less critical
Impact: Security Bypass
Where: From local network
Solution Status: Unpatched

OS:Fujitsu PRIMERGY BX300

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2007-3012


Description:
RedTeam Pentesting has reported a security issue in PRIMERGY BX300, which can be exploited by malicious people to bypass certain security restrictions.

The problem is that the web interface still displays the contents of an accessed page when the authentication dialog is canceled. This can be exploited to disclose certain system information by directly accessing certain pages and canceling the authentication dialog.

Solution:
Reportedly, the vendor will not issue a fix as the product is already discontinued.

Provided and/or discovered by:
RedTeam Pentesting

Original Advisory:
http://www.redteam-pentesting.de/advisories/rt-sa-2007-003.php


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Today
New advisories: 11
New vulnerabilities: 65
Updated advisories: 15

Less // 45 views
Ubuntu update for nfs-utils
Moderately // 49 views
Debian update for clamav
Moderately // 94 views
Red Hat update for ruby
Moderately // 96 views
SUSE update for kernel

Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 291 views
2. My Simple Forum "action" Local File Inclusion Vulnerability // 94 views
3. Red Hat update for java-1.5.0-sun / java-1.6.0-sun // 91 views
4. Adobe Flash Player Multiple Security Issues and Vulnerabilities // 90 views
5. BNCwi "newlanguage" File Inclusion Vulnerability // 79 views
6. SUSE update for kernel // 70 views
7. Red Hat update for ruby // 69 views
8. Nagios Unspecified CGI Vulnerability // 53 views
9. Linux Kernel PARISC "parisc_show_stack()" Denial of Service // 47 views
10. PHP ZipArchive::extractTo() Directory Traversal Vulnerability // 43 views