SECUNIA ADVISORY ID:
SA40838
VERIFY ADVISORY:
Secunia.com
http://secunia.com/advisories/40838/
Customer Area (Credentials Required)
https://ca.secunia.com/?page=viewadvisory&vuln_id=40838
RELEASE DATE:
2010-08-05
DISCUSS ADVISORY:
http://secunia.com/advisories/40838/#comments
DESCRIPTION:
A security issue has been reported in Novell ZENworks Server and
Desktop Management, which can be exploited by malicious people to
bypass certain security restrictions.
The problem is that a user, who has access to a managed device, is
able to authenticate into a remote session on another managed device
when both managed devices are configured with the same Remote
Management password (e.g. when a common password has been distributed
via NAL or TED).
SOLUTION:
The vendor recommends disabling password mode of authentication in
the Remote Management policy (disabled by default). Alternatively,
the vendor suggests to only distribute a common password via NAL or
TED in trusted environments.
PROVIDED AND/OR DISCOVERED BY:
The vendor credits TippingPoint ZDI.
ORIGINAL ADVISORY:
Novell:
http://www.novell.com/support/viewContent.do?externalId=7006557&sliceId=1
OTHER REFERENCES:
Further details available in Customer Area:
http://secunia.com/products/corporate/EVM/
DEEP LINKS:
Further details available in Customer Area:
http://secunia.com/products/corporate/EVM/
EXTENDED DESCRIPTION:
Further details available in Customer Area:
http://secunia.com/products/corporate/EVM/
EXTENDED SOLUTION:
Further details available in Customer Area:
http://secunia.com/products/corporate/EVM/
EXPLOIT:
Further details available in Customer Area:
http://secunia.com/products/corporate/EVM/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
private users keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------