An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning sudo privileges, C-MOR is vulnerable to a privilege escalation attack. The Linux user www-data running the C-MOR web interface can execute some OS commands as root via Sudo without having to enter the root password. These commands, for example, include cp, chown, and chmod, which enable an attacker to modify the system's sudoers file in order to execute all commands with root privileges. Thus, it is possible to escalate the limited privileges of the user www-data to root privileges.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Sep 2024 07:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | ||
Vendors & Products |
Za-internet
Za-internet c-mor Video Surveillance |
|
References |
| |
Metrics |
ssvc
|
Thu, 05 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Za-internet
Za-internet c-mor Video Surveillance |
|
Weaknesses | CWE-269 | |
CPEs | cpe:2.3:a:za-internet:c-mor_video_surveillance:5.2401:*:*:*:*:*:*:* | |
Vendors & Products |
Za-internet
Za-internet c-mor Video Surveillance |
|
Metrics |
cvssV3_1
|
Thu, 05 Sep 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning sudo privileges, C-MOR is vulnerable to a privilege escalation attack. The Linux user www-data running the C-MOR web interface can execute some OS commands as root via Sudo without having to enter the root password. These commands, for example, include cp, chown, and chmod, which enable an attacker to modify the system's sudoers file in order to execute all commands with root privileges. Thus, it is possible to escalate the limited privileges of the user www-data to root privileges. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-09-05T00:00:00
Updated: 2024-09-06T06:03:37.222Z
Reserved: 2024-08-22T00:00:00
Link: CVE-2024-45173
Vulnrichment
Updated: 2024-09-06T06:03:37.222Z
NVD
Status : Awaiting Analysis
Published: 2024-09-05T15:15:16.680
Modified: 2024-11-21T09:37:24.467
Link: CVE-2024-45173
Redhat
No data.