{"id":34567,"date":"2022-12-09T19:08:10","date_gmt":"2022-12-09T16:08:10","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/170178\/idcm51-escalate.txt"},"modified":"2022-12-11T09:48:42","modified_gmt":"2022-12-11T06:18:42","slug":"intel-data-center-manager-5-1-local-privilege-escalation","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/intel-data-center-manager-5-1-local-privilege-escalation\/","title":{"rendered":"Intel Data Center Manager 5.1 Local Privilege Escalation"},"content":{"rendered":"<p dir=\"ltr\" style=\"text-align: left;\">RCE Security Advisory<br \/>\nhttps:\/\/www.rcesecurity.com<\/p>\n<p dir=\"ltr\" style=\"text-align: left;\">1. ADVISORY INFORMATION<br \/>\n=======================<br \/>\nProduct: Intel Data Center Manager<br \/>\nVendor URL: https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/tools\/data-center-manager-console\/overview.html<br \/>\nType: Incorrect Use of Privileged APIs [CWE-648]\nDate found: 2022-07-16<br \/>\nDate published: 2022-12-07<br \/>\nCVSSv3 Score: 7.4 (CVSS:3.1\/AV:L\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H)<br \/>\nCVE: &#8211;<\/p>\n<p dir=\"ltr\" style=\"text-align: left;\">2. CREDITS<br \/>\n==========<br \/>\nThis vulnerability was discovered and researched by Julien Ahrens from<br \/>\nRCE Security.<\/p>\n<p dir=\"ltr\" style=\"text-align: left;\">3. VERSIONS AFFECTED<br \/>\n====================<br \/>\nIntel Data Center Manager 5.1 (latest) and below<\/p>\n<p dir=\"ltr\" style=\"text-align: left;\">4. INTRODUCTION<br \/>\n===============<br \/>\nEnergy costs are the fastest rising expense for today\u2019s data centers. Intel\u00ae Data<br \/>\nCenter Manager (Intel\u00ae DCM) provides real-time power and thermal consumption data,<br \/>\ngiving you the clarity you need to lower power usage, increase rack density, and<br \/>\nprolong operation during outages.<\/p>\n<p dir=\"ltr\" style=\"text-align: left;\">(from the vendor&#8217;s homepage)<\/p>\n<p dir=\"ltr\" style=\"text-align: left;\">5. VULNERABILITY DETAILS<br \/>\n========================<br \/>\nThe latest version (5.1) and all prior versions of Intel&#8217;s DCM are vulnerable to a<br \/>\nlocal privileges escalation vulnerability using the application user &#8220;dcm&#8221; used to<br \/>\nrun the web application and the rest interface. An attacker who gained RCE using<br \/>\nthis dcm user (i.e., through Log4j) is then able to escalate their privileges to<br \/>\nroot by abusing a weak Sudo configuration for the &#8220;dcm&#8221; user:<\/p>\n<p dir=\"ltr\" style=\"text-align: left;\">dcm ALL=(ALL) NOPASSWD:\/usr\/local\/bin\/SDPTool<br \/>\ndcm ALL=(ALL) NOPASSWD:\/usr\/bin\/cp<br \/>\ndcm ALL=(ALL) NOPASSWD:\/usr\/bin\/chmod<\/p>\n<p dir=\"ltr\" style=\"text-align: left;\">The Intel Server Debug and Provisioning Tool (SDP Tool) must be installed for the<br \/>\nData Center Manager to be vulnerable. Successful exploits can allow an authenticated<br \/>\nattacker to execute commands as root. In this way, the attacker can compromise the<br \/>\nvictim system&#8217;s entire confidentiality, integrity, and availability, thereby allowing<br \/>\nto persist within the attached network.<\/p>\n<p dir=\"ltr\" style=\"text-align: left;\">6. PROOF OF CONCEPT<br \/>\n===================<br \/>\nJust one way of exploitation is by replacing the current sudoers configuration:<\/p>\n<p dir=\"ltr\" style=\"text-align: left;\">1.Create a new sudoers configuration file using the compromised &#8220;dcm&#8221; user in i.e. \/tmp\/<br \/>\n2.sudo chmod 440 \/tmp\/sudoers<br \/>\n3.sudo cp sudoers \/etc\/sudoers<br \/>\n4.sudo \/bin\/bash<\/p>\n<p dir=\"ltr\" style=\"text-align: left;\">7. SOLUTION<br \/>\n===========<br \/>\nNone. Intel thinks that this is not a vulnerability and therefore does also not assign<br \/>\na CVE for it.<\/p>\n<p dir=\"ltr\" style=\"text-align: left;\">8. REPORT TIMELINE<br \/>\n==================<br \/>\n2022-07-16: Discovery of the vulnerability<br \/>\n2022-07-16: Reported to vendor via their bug bounty program<br \/>\n2022-07-18: Vendor response: Sent to &#8220;appropriate reviewers&#8221;<br \/>\n2022-07-26: Vendor states that the vulnerability &#8220;depends on something that does not exist (eg; RCE).&#8221;<br \/>\n2022-07-26: Sent a clarification that a compromise of the &#8220;dcm&#8221; account is indeed necessary, but there have been RCEs in the past (i.e. through Log4j)<br \/>\n2022-09-22: Vendor has troubles to reproduce the bug and asks for another PoC<br \/>\n2022-09-22: Sent a clarification about the PoC<br \/>\n2022-09-22: Vendor states that the report &#8220;does not clearly demonstrate a vulnerability in DCM&#8221; and the report will be closed.<br \/>\n2022-09-23: Provided the vendor with a PoC utilizing Log4shell (CVE-2021-44228) in a former version of DCM<br \/>\n2022-10-10: Vendor asks whether the Log4shell bug is still reproducible in the latest version of DCM<br \/>\n2022-10-10: Made clear that Log4shell is not the point about the report<br \/>\n2022-10-11: Vendor states &#8220;We do not clearly see a a vulnerability demonstrated in DCM&#8221;<br \/>\n2022-10-12: [Back and forth about the provided PoCs]\n2022-10-12: I&#8217;m giving up.<br \/>\n2022-12-07: Public disclosure<\/p>\n<p dir=\"ltr\" style=\"text-align: left;\">9. REFERENCES<br \/>\n==============<br \/>\nhttps:\/\/github.com\/MrTuxracer\/advisories<\/p>\n","protected":false},"excerpt":{"rendered":"<p>RCE Security Advisory https:\/\/www.rcesecurity.com 1. ADVISORY INFORMATION ======================= Product: Intel Data Center Manager Vendor URL: https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/tools\/data-center-manager-console\/overview.html Type: Incorrect Use of Privileged APIs [CWE-648] Date found: 2022-07-16 Date published: 2022-12-07 CVSSv3 Score: 7.4 (CVSS:3.1\/AV:L\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H) CVE: &#8211; 2. CREDITS ========== This vulnerability was discovered and researched by Julien Ahrens from RCE Security. 3. VERSIONS AFFECTED ==================== Intel &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-34567","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34567","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=34567"}],"version-history":[{"count":2,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34567\/revisions"}],"predecessor-version":[{"id":34622,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34567\/revisions\/34622"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=34567"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=34567"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=34567"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}