Описание
Security Onion v2 prior to 2.3.10 has an incorrect sudo configuration, which allows the administrative user to obtain root access without using the sudo password by editing and executing /home//SecurityOnion/setup/so-setup.
Ссылки
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- ExploitPatchThird Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- ExploitPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 2.0.0 (включая) до 2.3.10 (исключая)
cpe:2.3:a:securityonionsolutions:security_onion:*:*:*:*:*:*:*:*
EPSS
Процентиль: 18%
0.00057
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-306
EPSS
Процентиль: 18%
0.00057
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-306