mercredi 26 février 2020    || Inscription
BanniereAlertes
 
 

Notre sélection d'alertes et avis SSI.
Sources : US Cert, Cert EU, Cert FR, Cnil, VulDB.

mardi 26 mars 2019

Marel Food Processing Systems Pluto Platform SSH Server privilege escalation

A vulnerability, which was classified as critical, has been found in Marel Food Processing Systems Pluto Platform. Affected by this issue is some functionality of the component SSH Server. The manipulation with an unknown input leads to a privilege escalation vulnerability. Using CWE to declare the problem leads to CWE-269. Impacted is confidentiality, integrity, and availability. CVE summarizes:

Systems using the Marel Food Processing Systems Pluto platform do not restrict remote access. Marel has created an update for Pluto-based applications. This update will restrict remote access by implementing SSH authentication.

The weakness was disclosed 03/27/2019. This vulnerability is handled as CVE-2017-9626 since 06/14/2017. The technical details are unknown and an exploit is not available.

Upgrading eliminates this vulnerability.Addressing this vulnerability is possible by firewalling ssh. The best possible mitigation is suggested to be upgrading to the latest version.

Product

Vendor

Product

CPE

CVSSv3

VulDB Meta Base Score: 5.5
VulDB Meta Temp Score: 5.3

VulDB Base Score: ≈5.5
VulDB Temp Score: ≈5.3
VulDB Vector: 🔒
VulDB Reliability: 🔍

CVSSv2

VulDB Base Score: 🔒
VulDB Temp Score: 🔒
VulDB Reliability: 🔍

Exploiting

Class: Privilege escalation (CWE-269)
Local: Yes
Remote: No

Availability: 🔒
Status: Not defined

Price Prediction: 🔍
Current Price Estimation: 🔒

Threat Intelligence

Threat: 🔍
Adversaries: 🔍
Geopolitics: 🔍
Economy: 🔍
Predictions: 🔍
Remediation: 🔍

Countermeasures

Recommended: Upgrade
Status: 🔍
0-Day Time: 🔒

Firewalling: 🔒

Timeline

06/14/2017 CVE assigned
03/27/2019 Advisory disclosed
03/28/2019 VulDB entry created
03/28/2019 VulDB last update

Sources

CVE: CVE-2017-9626 (🔒)

Entry

Created: 03/28/2019 11:31 AM
Complete: 🔍

Lien vers l'article source

Auteur: VulDB

Catégories: VulDBNombre de vues: 81

x

Événements SSI