ID

VAR-201310-0373


CVE

CVE-2013-5781


TITLE

Sun System Firmware Run in Oracle SPARC Enterprise T4 On the server Sun System Firmware/Integrated Lights Out Manager Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2013-004714

DESCRIPTION

Unspecified vulnerability in Oracle PARC Enterprise T4 Servers running Sun System Firmware before 8.3.0.b allows local users to affect confidentiality, integrity, and availability via vectors related to Sun System Firmware/Integrated Lights Out Manager (ILOM). (DoS) An attack may be carried out. The 'Sun System Firmware/Integrated Lights Out Manager (ILOM)' sub component is affected. This vulnerability affects the following supported versions: Sun System Firmware before 8.3.0.b. A remote attacker can exploit this vulnerability to execute arbitrary code, affecting data confidentiality, integrity, and availability

Trust: 1.98

sources: NVD: CVE-2013-5781 // JVNDB: JVNDB-2013-004714 // BID: 63051 // VULHUB: VHN-65783

AFFECTED PRODUCTS

vendor:oraclemodel:sparc t4-1bscope:eqversion: -

Trust: 1.0

vendor:oraclemodel:sun systemscope:lteversion:8.3.0

Trust: 1.0

vendor:oraclemodel:sparc t4-4scope:eqversion: -

Trust: 1.0

vendor:oraclemodel:sparc t4-1scope:eqversion: -

Trust: 1.0

vendor:oraclemodel:sparc t4-1scope: - version: -

Trust: 0.8

vendor:oraclemodel:sparc t4-1bscope: - version: -

Trust: 0.8

vendor:oraclemodel:sparc t4-4scope: - version: -

Trust: 0.8

vendor:oraclemodel:sun systemscope:ltversion:8.3.0.b

Trust: 0.8

vendor:oraclemodel:sun systemscope:eqversion:8.3.0

Trust: 0.6

vendor:avayamodel:irscope:eqversion:4.0

Trust: 0.3

sources: BID: 63051 // JVNDB: JVNDB-2013-004714 // CNNVD: CNNVD-201310-361 // NVD: CVE-2013-5781

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-5781
value: MEDIUM

Trust: 1.0

NVD: CVE-2013-5781
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201310-361
value: MEDIUM

Trust: 0.6

VULHUB: VHN-65783
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2013-5781
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-65783
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-65783 // JVNDB: JVNDB-2013-004714 // CNNVD: CNNVD-201310-361 // NVD: CVE-2013-5781

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2013-5781

THREAT TYPE

local

Trust: 0.9

sources: BID: 63051 // CNNVD: CNNVD-201310-361

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201310-361

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-004714

PATCH

title:Oracle Critical Patch Update Advisory - October 2013url:http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html

Trust: 0.8

title:Text Form of Oracle Critical Patch Update - October 2013 Risk Matricesurl:http://www.oracle.com/technetwork/topics/security/cpuoct2013verbose-1899842.html

Trust: 0.8

title:October 2013 Critical Patch Update Releasedurl:https://blogs.oracle.com/security/entry/october_2013_critical_patch_update

Trust: 0.8

sources: JVNDB: JVNDB-2013-004714

EXTERNAL IDS

db:NVDid:CVE-2013-5781

Trust: 2.8

db:JVNDBid:JVNDB-2013-004714

Trust: 0.8

db:CNNVDid:CNNVD-201310-361

Trust: 0.7

db:BIDid:63051

Trust: 0.4

db:VULHUBid:VHN-65783

Trust: 0.1

sources: VULHUB: VHN-65783 // BID: 63051 // JVNDB: JVNDB-2013-004714 // CNNVD: CNNVD-201310-361 // NVD: CVE-2013-5781

REFERENCES

url:http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-5781

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-5781

Trust: 0.8

sources: VULHUB: VHN-65783 // JVNDB: JVNDB-2013-004714 // CNNVD: CNNVD-201310-361 // NVD: CVE-2013-5781

CREDITS

Oracle

Trust: 0.3

sources: BID: 63051

SOURCES

db:VULHUBid:VHN-65783
db:BIDid:63051
db:JVNDBid:JVNDB-2013-004714
db:CNNVDid:CNNVD-201310-361
db:NVDid:CVE-2013-5781

LAST UPDATE DATE

2024-11-23T22:49:34.111000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-65783date:2013-10-16T00:00:00
db:BIDid:63051date:2013-11-15T00:54:00
db:JVNDBid:JVNDB-2013-004714date:2013-10-18T00:00:00
db:CNNVDid:CNNVD-201310-361date:2013-10-18T00:00:00
db:NVDid:CVE-2013-5781date:2024-11-21T01:58:06.877

SOURCES RELEASE DATE

db:VULHUBid:VHN-65783date:2013-10-16T00:00:00
db:BIDid:63051date:2013-10-15T00:00:00
db:JVNDBid:JVNDB-2013-004714date:2013-10-18T00:00:00
db:CNNVDid:CNNVD-201310-361date:2013-10-18T00:00:00
db:NVDid:CVE-2013-5781date:2013-10-16T15:55:34.460