n.runs AG - Das Unternehmen Sicherheit
 
 
The Company
LEISTUNGSSPEKTRUM
IT INFRASTRUKTUR
IT SICHERHEIT SECURITY
IT BUSINESS CONSULTING
IT SOFTWARE

n.runs AG
Nassauer Straße 60
61440 Oberursel
Telefon: +49 (0) 6171/699-0
Telefax: +49 (0) 6171/699-199
E-mail: contact@nruns.com
Newsletter anfordern
Impressum

n.runs-SA-2008.009 Eaton MGE OPS Network Shutdown Module authentication bypass

n.runs AG
http://www.nruns.com
n.runs-SA-2008.009

security(at)nruns.com
27-October-2008

* * *


Vendor: Eaton MGE office protection systems
Affected Products:
   - Network Shutdown Module version 3.10

Vulnerability: Authentication bypass vulnerability and remote code execution
Risk: High

Vendor communication:

2008/08/13 initial notification of EATON MGE Office Protection
Systems (MGEOPS)
2008/08/20 second notification of MGEOPS
2008/08/20 MGEOPS confirmation of receiving information
2008/08/25 receiving patch proposal from MGEOPS
2008/08/29 confirmation of proper patch, asking of release date
2008/09/02 awaiting feedback regarding release date of the patch
2008/09/18 patch and new version undergoing QA process of MGEOPS
still no release date known
2008/10/07 another request regarding the release date
2008/10/21 MGEOPS informs n.runs AG about release of the new
software version
2008/10/27 n.runs AG releases this advisory


Overview:

EATON MGE Office Protection Systems designs and manufactures secured
power products and solutions for enterprises, small business and homes.
The Network Shutdown Module continuously wait for information from the
Management Proxy or Management Card connected to the EATON UPS and warns
administrators and users if AC power fails and proceeds with graceful
system shutdown before the end of battery backup power is reached..


Description:

Remote exploitation of an authentication bypass vulnerability could
allow an attacker to execute arbitrary code.
In detail, the following flaw was determined:

- Remote exploitation of an authentication bypass vulnerability could allow an attacker to execute arbitrary code. In detail, the following flaw was determined:
- Custom actions can be added to the MGE frontend without authentication required (pane_actionbutton.php)
- Actions can be executed (tested) without authentication required (exec_action.php)


Impact:

 

This problem can lead to a remote file execution vulnerability. It can
allow an attacker to add and execute custom actions. The commands to be
executed are included within the added action.

The vulnerability is present in MGE Network Shutdown Module software
versions prior 3.10 build 13.
 
Solution:

 

EATON MGE Office Protection Systems has issued an update to correct this
vulnerability. A new version of the software (version 3.20) can be found at:
http://download.mgeops.com/explore/eng/network/net_sol.htm
 
Credit:

 

 Bug found by Jan Rossmann and Jan Wagner of n.runs AG.
 
References:

This Advisory and Upcoming Advisories:
http://www.nruns.com/security_advisory.php

Subscribe to the n.runs newsletter by signing up to:
http://www.nruns.com/newsletter_en.php


Unaltered electronic reproduction of this advisory is permitted. For all other reproduction or publication, in printing or otherwise, contact security@nruns.com for permission. Use of the advisory constitutes acceptance for use in an "as is" condition. All warranties are excluded. In no event shall n.runs be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if n.runs has been advised of the possibility of such damages.

Copyright 2008 n.runs AG. All rights reserved. Terms of use apply.
Penetration Test
 

17 Dezember 2008:
Advisory: HTML parsing flaw lead to remote code execution 

* * *

27 Oktober 2008:
Advisory: Eaton MGE OPS Network Shutdown Module authentication bypass and code execution

* * *

21 Oktober 2008:
Advisory: Internet Explorer HTML Object Memory Corruption

* * *

20 Oktober 2008:
Pressemitteilung
n.runs und Avira geben strategische Partnerschaft im IT-Sicherheitsumfeld bekannt

* * *

14 Oktober 2008:
Pressemitteilung
SYSTEMS 2008: n.runs AG präsentiert Bollwerk gegen den „Feind im eigenen Netz“ und Microsoft "Security Development Lifecycle Pro Network"

* * *

30 September 2008:
Corporate News
Zahlen des ersten Halbjahreszahlen 2008 bestätigen Expansionskurs
+++ Umsatzerlöse steigen um knapp 30 Prozent auf EUR 3,32 Millionen
+++ EBITDA um EUR 0,27 Millionen auf EUR -0,35 Millionen verbessert
+++ Ergebnis von Softwareinvestitionen geprägt, Consulting profitabel
+++ Ausblick 2008


* * *

17 September 2008:
Corporate News
n.runs wird durch Microsoft als Mitglied des neuen Programms Microsoft Security Development Lifecyle Pro Network berufen
+++ n.runs AG exklusives Mitglied im Microsoft SDL Pro Network
+++ Einziges Mitglied des MS SDL Pro Network auf europäischem Festland
+++ Mittelfristiger Umsatzbeitrag von über 10 Prozent geplant


* * *

17 September 2008:
Pressemitteilung
Software-Gigant beruft IT-Sicherheitsunternehmen zum Mitglied des "Microsoft Security Development Lifecycle Pro Network" Microsoft setzt im Rahmen ihres neuen Partnerprogramms "SDL Pro Network" in EMEA auf die n.runs AG

* * *

10 September 2008:
Advisory
Cross-Site Scripting Filter Evasion in various frameworks and applications

* * *

10 September 2008:
Advisory
Horde Framework Cross-Site Scripting in filename MIME attachments

* * *

25 August 2008:
Press-Release
IT-Sicherheit für Regierungen und Militär:
n.runs und Thales kooperieren


* * *

20 August 2008:
Artikel
"IT-Grundschutz" des BSI und secumedia Verlages - Antivirensoftware :
Wegbereiter für
Datendiebe


* * *

20 August 2008:
Press Release
Wachsende Bedrohung:
folgenschwere Angriffe auf E-Mail-/AV-Systeme nehmen stetig zu.


* * *