Executive brief
The SGI MachineInfo CGI program, which is installed by default on certain web servers, allows remote users to view sensitive system status information. This data can be used by attackers to map out the internal network or identify further vulnerabilities for a more targeted attack. Exposure of this information can compromise the overall security posture of the organization's infrastructure.
Technical details
The vulnerability is an information disclosure flaw within the MachineInfo CGI script, typically located in /var/www/cgi-bin/. The script is part of the SGI Outbox or SysAdm subsystems and is often installed by default on IRIX systems. A remote, unauthenticated attacker can access this script via a standard HTTP request to retrieve detailed system status and configuration information. This information gathering can serve as a precursor to more complex attacks by providing the attacker with technical details about the host environment. Mitigation involves disabling access to the CGI script or removing the affected subsystem.
Affected products
- SGI IRIX 6.3 and earlier
Timeline
- 1997-05-01: advisory: SGI Security Advisory 19970501-01-A released
- 1997-05-07: disclosed: Public discussion on Bugtraq mailing list
- 1997-05-07: advisory: NVD published date