=====================================================================
                                     CERT-Renater

                          Note d'Information No. 2007/VULN100
_____________________________________________________________________

DATE                      : 13/03/2007

HARDWARE PLATFORM(S)      : Sun Fire X2100 M2 Server, Sun Fire X2200 M2 Server.

OPERATING SYSTEM(S)       : Solaris systems running ipmitool.

======================================================================

Sun(sm) Alert Notification

     * Sun Alert ID: 102828
     * Synopsis: Security Vulnerability in the ipmitool(1m) Interface to the
       Sun Fire X2100M2 and X2200M2 Servers
     * Category: Security
     * Product: Sun Fire X2100 M2 Server, Sun Fire X2200 M2 Server
     * BugIDs: 6514224
     * Avoidance: Upgrade
     * State: Resolved
     * Date Released: 07-Mar-2007
     * Date Closed: 07-Mar-2007
     * Date Modified:

1. Impact

    A security vulnerability in the ipmitool(1m) utility may allow an
    unprivileged user to gain unauthorized administrative privileges and then be
    able to reset or power off a local or remote SunFire X2100M2 or SunFire
    X2200M2 server.

2. Contributing Factors

    This issue can occur on the following platforms:

    x86 Platform

      * Sun Fire X2100M2 without BMC/SP Firmware 2.91
      * Sun Fire X2200M2 without BMC/SP Firmware 2.91

    Notes:

       1. The ipmitool(1m) is used for remote monitoring of Sun x64 systems and
          therefore does not affect the SPARC platform.
       2. This issue does not affect any other x64 systems apart from the Sun
          Fire X2100M2 and Sun Fire X2200M2.

    To determine the current firmware revision on the system, the following
    command can be run:

     # ipmitool -H <ipaddress> -U <username> -P <password> mc info
     Device ID                 : 5
     Device Revision           : 0
     Firmware Revision         : 2.91
     IPMI Version              : 2.0
     Manufacturer ID           : 7244
     Manufacturer Name         : Unknown (0x1c4c)
     Product ID                : 21305 (0x5339)
     Device Available          : yes
     Provides Device SDRs      : yes

3. Symptoms

    There are no predictable symptoms that would indicate the described
    vulnerability has been exploited.


Solution Summary

4. Relief/Workaround

    There is no workaround for this issue. Please see the Resolution section
    below.

5. Resolution

    This issue is addressed on the following platforms:

    x86 Platform

        * Sun Fire X2100M2 with BMC/SP Firmware 2.91 (included with M2 Server
          1.4 CD ISO release) at
          http://www.sun.com/servers/entry/x2100/downloads.jsp
        * Sun Fire X2200M2 with BMC/SP Firmware 2.91 (included with M2 Server
          1.4 CD ISO release) at
          http://www.sun.com/servers/x64/x2200/downloads.jsp

This Sun Alert notification is being provided to you on an "AS IS" basis. This
Sun Alert notification may contain information provided by third parties. The
issues described in this Sun Alert notification may or may not impact your
system(s). Sun makes no representations, warranties, or guarantees as to the
information contained herein. ANY AND ALL WARRANTIES, EXPRESS OR IMPLIED,
INCLUDING WITHOUT LIMITATION WARRANTIES OF MERCHANTABILITY, FITNESS FOR A
PARTICULAR PURPOSE, OR NON-INFRINGEMENT, ARE HEREBY DISCLAIMED. BY ACCESSING
THIS DOCUMENT YOU ACKNOWLEDGE THAT SUN SHALL IN NO EVENT BE LIABLE FOR ANY
DIRECT, INDIRECT, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES THAT ARISE
OUT OF YOUR USE OR FAILURE TO USE THE INFORMATION CONTAINED HEREIN. This Sun
Alert notification contains Sun proprietary and confidential information. It
is being provided to you pursuant to the provisions of your agreement to
purchase services from Sun, or, if you do not have such an agreement, the
Sun.com Terms of Use. This Sun Alert notification may only be used for the
purposes contemplated by these agreements.

Copyright 2000-2006 Sun Microsystems, Inc., 4150 Network Circle, Santa Clara,
CA 95054 U.S.A. All rights reserved.

======================================================================

            =========================================================
            Les serveurs de référence du CERT-Renater
            http://www.urec.fr/securite
            http://www.cru.fr/securite
            http://www.renater.fr
            =========================================================
            + CERT-RENATER          | tel : 01-53-94-20-44          +
            + 151 bd de l'Hopital   | fax : 01-53-94-20-41          +
            + 75013 Paris           | email: certsvp@renater.fr     +
            =========================================================






