APP: Novell ZENworks Configuration Management PreBoot Service Overflow

This signature detects attempts to exploit a known vulnerability in the Novell ZENworks Configuration Management. A successful attack can lead to a buffer overflow and arbitrary remote code execution with elevated privileges. Failed exploit attempts could lead to a denial of service condition.

Extended Description

Novell ZENworks Configuration Management is prone to following vulnerabilities: 1. A stack-based buffer-overflow vulnerability 2. An arbitrary file download vulnerability Exploiting these issues may allow remote attackers to execute arbitrary code or retrieve arbitrary files within the context of the affected application.

Affected Products

Novell zenworks_configuration_management

Short Name
APP:NOVELL:ZENWORKS-CONFMGR-BO
Severity
Major
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
CVE-2011-3175 CVE-2011-3176 Configuration Management Novell Overflow PreBoot Service ZENworks bid:52659
Release Date
01/08/2013
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

srx-branch-12.3

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx-12.3

vmx-19.3

srx-12.3

Sigpack Version
3336
Port
TCP/998
False Positive
Unknown
Vendors

Novell

CVSS Score

10.0

Found a potential security threat?