Short Name |
APP:SECURECRT-CONF |
---|---|
Severity |
Minor |
Recommended |
No |
Category |
APP |
Keywords |
SecureCRT Configuration File in TELNET URL |
Release Date |
2004/12/13 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects TELNET URLs that specify a SecureCRT configuration folder option. SecureCRT prior to 4.1.9 contain a vulnerability that allows configurations files to contain login script information. An attacker can entice a target to open a TELNET URL that specifies an external configuration file containing an arbitrary script.
A remote command execution vulnerability affects Van Dyke's SecureCRT. This issue is due to a design error that allows a remote attacker to execute arbitrary script on the affected computer with the privileges of the affected application. An attacker may leverage this issue to execute arbitrary code with the privileges of the user that activated the affected application; this may facilitate privilege escalation or unauthorized access.