[CVE-2017-1205] IBM Spectrum LSF Privilege Escalation

2018-03-19 Thread john . fitzpatrick
###[IBM Spectrum LSF Privilege Escalation]### * Software: IBM Spectrum LSF * Affected Versions: IBM Spectrum LSF 8.3, 9.1.1, 9.1.2, 9.1.3, 10.1, 10.1.0.1 * CVE Reference: CVE-2017-1205 * Author: John Fitzpatrick (@j0hn__f) * Severity: CVSS 9.3 * Vendor: IBM * Vendor Response: Fixes provided

[MWR-2016-0002] DDN Default SSH Keys

2016-06-15 Thread john . fitzpatrick
###[DDN Default SSH Keys]### DDN SFA devices have default SSH keys in place * Product: DDN SFA storage devices, all versions, all models * Severity: High * CVE Reference: NO CVE ASSIGNED - MWR ref: MWR-2016-0002 * Type: Default Credentials * Author: John Fitzpatrick * Date: 2016-06-15

[MWR-2016-0001] DDN Insecure Update Mechanism

2016-06-15 Thread john . fitzpatrick
: John Fitzpatrick * Date: 2016-06-15 ## Description The mechanism used for updating firmware on DDN controllers is insecure allowing for privilege escalation to root. ## Impact Exploitation of this issue can allow for code execution as root allowing an adversary to gain full access

[CVE-2016-0392] IBM GPFS / Spectrum Scale Command Injection

2016-06-07 Thread john . fitzpatrick
###[IBM GPFS / Spectrum Scale Command Injection]### A command injection vulnerability in GPFS / Spectrum Scale allows attackers to escalate privileges to root * Product: IBM GPFS / Spectrum Scale * Severity: High * CVE Reference: CVE-2016-0392 * Type: Command injection * Author: John

[CVE-2014-7303] SGI Tempo System Database Exposure

2014-12-10 Thread john . fitzpatrick
[SGI Tempo System Database Exposure] Software: SGI Tempo (SGI ICE-X Supercomputers) Affected Versions: Unknown CVE Reference: CVE-2014-7303 Author: John Fitzpatrick, MWR Labs Severity: Low Risk Vendor: Silicon Graphics International Corp (SGI) Vendor Response: Uncooperative [Description

[CVE-2014-7302] SGI SUID Root Privilege Escalation

2014-12-10 Thread john . fitzpatrick
[SGI SUID Root Privilege Escalation] Software: SGI Tempo (SGI ICE-X Supercomputers) Affected Versions: Unknown CVE Reference: CVE-2014-7302 Author: Luke Jennings, John Fitzpatrick, MWR Labs Severity: Medium Risk Vendor: Silicon Graphics International Corp (SGI) Vendor Response: Uncooperative

[CVE-2014-7301] SGI Tempo System Database Password Exposure

2014-12-10 Thread john . fitzpatrick
[SGI Tempo System Database Password Exposure] Software: SGI Tempo (SGI ICE-X Supercomputers) Affected Versions: Unknown CVE Reference: CVE-2014-7301 Author: John Fitzpatrick, MWR Labs Severity: Medium Risk Vendor: Silicon Graphics International Corp (SGI) Vendor Response: Uncooperative

Moab Authentication Bypass [CVE-2014-5300]

2014-09-29 Thread john . fitzpatrick
##[Moab Authentication Bypass : CVE-2014-5300]## Software: Moab Affected Versions: All versions prior to Moab 7.2.9 and Moab 8 CVE Reference: CVE-2014-5300 Author: John Fitzpatrick, MWR Labs (http://labs.mwrinfosecurity.com/) Severity: High Risk Vendor: Adaptive Computing Vendor Response

Moab User Impersonation [CVE-2014-5375]

2014-09-29 Thread john . fitzpatrick
##[Moab User Impersonation : CVE-2014-5375]## Software: Moab Affected Versions: All current versions of Moab. However, the impact is limited in Moab 7.2.9 and Moab 8. CVE Reference: CVE-2014-5375 Author: John Fitzpatrick, Luke Jennings MWR Labs (http://labs.mwrinfosecurity.com/) Severity: High

Moab Authentication Bypass (insecure message signing) [CVE-2014-5376]

2014-09-29 Thread john . fitzpatrick
##[Moab Authentication Bypass (insecure message signing) : CVE-2014-5376]## Software: Moab Affected Versions: Dependent on configuration, can affect all versions of Moab including Moab 8 CVE Reference: CVE-2014-5376 Author: John Fitzpatrick, Luke Jennings MWR Labs (http

[CVE-2014-0749] TORQUE Buffer Overflow

2014-05-15 Thread john . fitzpatrick
to and including 2.5.13 CVE Reference: CVE-2014-0749 Authors: John Fitzpatrick (MWR Labs) Severity: High Risk Vendor: Adaptive Computing Vendor Response: Incorporated MWR supplied fix into 2.5 development branch, no advisory [Description] A buffer overflow exists in older versions of TORQUE which can

[mwrlabs advisory][CVE-2014-0748] Cray Aprun/Apinit Privilege Escalation

2014-02-11 Thread john . fitzpatrick
to mitigate this issue. [Software]: Aprun/apinit (Cray) [Affected Versions]: This issue was resolved in CLE 5.1.UP00 CLE 4.2.UP02 [CVE Reference]: CVE-2014-0748 [Authors]: John Fitzpatrick Luke Jennings [Severity]: High Risk [Vendor]: Cray inc. [Vendor Response]: Acknowledged, resolved, update