[33815] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Fw: APC 9606 SmartSlot Web/SNMP management card "backdoor" - MORE PROBLEMS

daemon@ATHENA.MIT.EDU (James Green)
Wed Feb 18 17:53:32 2004

From: James Green <james@stealthnet.co.uk>
To: bugtraq@securityfocus.com
Date: Tue, 17 Feb 2004 22:56:58 +0000
In-Reply-To: <OF655033A0.B934768B-ON03256E3D.00631297-03256E3D.00657440@lightrio.com.br>
MIME-Version: 1.0
Content-Type: text/plain;
  charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Message-Id: <200402172256.58290.james@stealthnet.co.uk>

On Tuesday 17 Feb 2004 6:23 pm, thiago.vazquez@light.com.br wrote:
> We have many products from APC and we've tested that vulnerability in some
> of them and ..... following are the results.

[ snip ]

According to a Matias Kvaternik at APC (US) today, the bug was discovered 
after the AP9606 was discontinued (we bought some less than one year ago), 
and the engineering team has "no fix in the pipeline". He advises us to 
switch off telnet access.

I would imagine most APC products are installed to last for a good three to 
six years - upgrading power hardware is probably about as practical as 
upgrading a load of networking equipment. I'm surprised, indeed disappointed, 
that APC doesn't appear to provide critical security fixes for these 
discontinued products; although I do only speak from very limited experience 
of APC.


James Green


home help back first fref pref prev next nref lref last post