Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2016-1542

Description

The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and enumerate users by sending an action packet to xmlrpc after an authorization failure.

POC

Reference

- http://packetstormsecurity.com/files/136461/BMC-Server-Automation-BSA-RSCD-Agent-User-Enumeration.html

- https://www.exploit-db.com/exploits/43902/

- https://www.exploit-db.com/exploits/43939/

Github

- https://github.com/7hang/cyber-security-interview

- https://github.com/ARPSyndicate/cvemon

- https://github.com/NickstaDB/PoC

- https://github.com/bao7uo/bmc_bladelogic

- https://github.com/blamhang/bmc_rscd_rce

- https://github.com/patriknordlen/bladelogic_bmc-cve-2016-1542