Vulnerability Description
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading /etc/odapw.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Sgi Tempo | - |
Related Weaknesses (CWE)
References
- https://labs.f-secure.com/advisories/sgi-tempo-system-database-password-exposureExploitThird Party Advisory
- https://packetstormsecurity.com/files/129466/SGI-Tempo-Database-Password-DisclosExploitThird Party AdvisoryVDB Entry
- https://labs.f-secure.com/advisories/sgi-tempo-system-database-password-exposureExploitThird Party Advisory
- https://packetstormsecurity.com/files/129466/SGI-Tempo-Database-Password-DisclosExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2014-7301?
CVE-2014-7301 is a vulnerability with a CVSS score of 6.6 (MEDIUM). SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading /et...
How severe is CVE-2014-7301?
CVE-2014-7301 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-7301?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Sgi Tempo.