Описание
Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python user to root via a symlink attack that uses chown, related to /etc/init.d/S50dropbear.sh and the /WEB/python/.ssh directory.
Ссылки
- Third Party Advisory
- ExploitThird Party Advisory
- Release NotesVendor Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.2.30.6 (исключая)
Одновременно
cpe:2.3:o:digi:connectport_x2e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:digi:connectport_x2e:-:*:*:*:*:*:*:*
EPSS
Процентиль: 27%
0.00097
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-59
Связанные уязвимости
github
больше 3 лет назад
Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python user to root via a symlink attack that uses chown, related to /etc/init.d/S50dropbear.sh and the /WEB/python/.ssh directory.
EPSS
Процентиль: 27%
0.00097
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-59