Executive brief
A vulnerability exists in the crp component of Hewlett Packard Apollo Domain OS, an operating system used in legacy workstation environments. A remote attacker can exploit this flaw to gain full administrative control (root privileges) over the system. This could lead to a complete compromise of the machine, including the theft of all data and the ability to disrupt operations.
Technical details
The vulnerability is located in the 'crp' (Create Remote Process) utility within HP Apollo Domain OS versions SR10 through SR10.3. It stems from the use of insecure system calls, specifically pad_$dm_cmd and pad_$def_pfk(), which can be abused by remote attackers. By leveraging these calls, an unauthenticated attacker can execute commands with root-level privileges over the network. This flaw allows for complete system compromise, including full access to the file system and administrative functions. Patch information is historically referenced in CERT advisory CA-1991-23.
Affected products
- Hewlett Packard Apollo Domain OS SR10 through SR10.3
Timeline
- 1991-12-18: disclosed: Initial publication date
- 1991-12-18: advisory: NVD published date