Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c23g-cgv4-p67j

Опубликовано: 09 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a binary that is configured with the cap_dac_override capability. This capability allows the process to bypass file system permission checks, resulting in unrestricted file system access. This could allow a local attacker to escalate privileges leading to arbitrary file modification and gaining root privileges on the system.

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a binary that is configured with the cap_dac_override capability. This capability allows the process to bypass file system permission checks, resulting in unrestricted file system access. This could allow a local attacker to escalate privileges leading to arbitrary file modification and gaining root privileges on the system.

EPSS

Процентиль: 11%
0.00206
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-250

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 месяцев назад

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a binary that is configured with the cap_dac_override capability. This capability allows the process to bypass file system permission checks, resulting in unrestricted file system access. This could allow a local attacker to escalate privileges leading to arbitrary file modification and gaining root privileges on the system.

CVSS3: 8.8
fstec
около 2 месяцев назад

Уязвимость программного обеспечения для управления сетевой инфраструктурой SINEC INS (Infrastructure Network Services), связанная с ошибками при управлении привилегиями, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 11%
0.00206
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-250