Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-75cr-rjwp-w5rp

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python user to root via a symlink attack that uses chown, related to /etc/init.d/S50dropbear.sh and the /WEB/python/.ssh directory.

Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python user to root via a symlink attack that uses chown, related to /etc/init.d/S50dropbear.sh and the /WEB/python/.ssh directory.

EPSS

Процентиль: 27%
0.00097
Низкий

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.8
nvd
почти 5 лет назад

Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python user to root via a symlink attack that uses chown, related to /etc/init.d/S50dropbear.sh and the /WEB/python/.ssh directory.

EPSS

Процентиль: 27%
0.00097
Низкий

Дефекты

CWE-59