|
|
|
|
| |
| A security vulnerability in Nokia's Firewall implementation allows authenticated users to cause a buffer overflow in the product, causing it to execute arbitrary code. |
| |
Credit:
The information has been provided by K2.
|
| |
Vulnerable systems:
IPSO scrooge 3.2.1-fcs1 releng 849 11.24.1999-102644 i386
FW-1, 4.1 SP2.
It is possible to execute arbitrary code on a machine running Nokia's firewall.
Even though only authenticated users can perform this attack, all which is needed, is that a firewall administrative account (doesn't have to have the highest permission settings on the firewall) to be compromised for the complete firewall to be compromised.
Exploit:
A request to Nokia's Firewall default HTTP administration server that will be of the form of:
http://127.0.0.1/cgi-bin/html_page?(Ax6000)&TEMPLATE=main
|
|
|
|
|
|
|
|
|
|