Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-16834

Опубликовано: 16 нояб. 2017
Источник: nvd
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pnp4nagios:pnp4nagios:*:*:*:*:*:*:*:*
Версия до 0.6.26 (включая)

EPSS

Процентиль: 11%
0.00038
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 8 лет назад

PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account.

CVSS3: 6.7
redhat
около 8 лет назад

PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account.

CVSS3: 7.8
debian
около 8 лет назад

PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an u ...

CVSS3: 7.8
github
больше 3 лет назад

PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account.

EPSS

Процентиль: 11%
0.00038
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-732