The Sun SPARC Enterprise M4000 and M5000 Server, within a certain range of serial numbers, allows remote attackers to use the manufacturing root password, perform a root login to the eXtended System Control Facility Unit (aka XSCFU or Service Processor), and have unspecified other impact.
References
Link | Resource |
---|---|
http://sunsolve.sun.com/search/document.do?assetkey=1-26-249126-1 | Vendor Advisory |
http://www.securityfocus.com/bid/33280 | |
http://www.securitytracker.com/id?1021602 | |
http://www.vupen.com/english/advisories/2009/0207 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2009-01-16 13:30
Updated : 2011-06-12 21:00
NVD link : CVE-2009-0171
Mitre link : CVE-2009-0171
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
sun
- sparc_enterprise_server