CVE-2000-0117: High severity Sun Cobalt Raq 3i vulnerability
The siteUserMod.cgi program in Cobalt RaQ2 servers allows any Site Administrator to modify passwords for other users, site administrators, and possibly admin (root).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Sun Cobalt RaQ siteUserMod.cgifrom your environment.Delete or remove the siteUserMod.cgi script from the server (or from any web-accessible cgi-bin) if it is not required.
- Configuration
Disable execution of the siteUserMod.cgi script (for example, remove execute permissions, move/rename the script, or update web server config to prevent access) to stop Site Administrators from using it to change other users' passwords.
Cobalt RaQ (siteUserMod.cgi) siteUserMod.cgi executable = disabled - Compensating control
Restrict access to RaQ administrative interfaces and Site Administrator functions to trusted IP ranges or via VPN, and limit assignment of Site Administrator privileges until the issue is remediated.
- Operational
Audit accounts and logs for unauthorized password changes; rotate passwords for site administrator accounts, user accounts, and the admin (root) account that may have been modified.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0117?
CVE-2000-0117 is considered a high severity vulnerability due to its ability to allow unauthorized password modifications.
How do I fix CVE-2000-0117?
To fix CVE-2000-0117, ensure that siteUserMod.cgi is secured and access is restricted to authorized users only.
Which systems are affected by CVE-2000-0117?
CVE-2000-0117 affects Sun Cobalt RaQ servers, including versions 1.0, 2, and 3i.
Can CVE-2000-0117 lead to a complete system compromise?
Yes, CVE-2000-0117 can lead to complete system compromise since it allows unauthorized access to modify admin passwords.
What is the potential impact of exploiting CVE-2000-0117?
Exploiting CVE-2000-0117 could allow an attacker to take control of user accounts and potentially gain full administrative access.