Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Bryan Rhodes

#17484de 53,635
15.3CVSS total
Vulnerabilidades · 2
Alta
2
PT-2019-9974
7.8
2019-04-25
Cerner · Cerner Connectivity Engine · CVE-2018-20052
**Name of the Vulnerable Software and Affected Versions** Cerner Connectivity Engine (CCE) version 4 **Description** An issue was discovered where the user running the main CCE firmware has NOPASSWD sudo privileges to several utilities, which could be used to escalate privileges to root. For example, the command "sudo ln -s /tmp/script /etc/cron.hourly/script" could be utilized. **Recommendations** For Cerner Connectivity Engine (CCE) version 4, restrict the sudo privileges of the user running the main CCE firmware to prevent escalation to root. As a temporary workaround, consider disabling the use of sudo for the affected utilities until a more permanent solution is implemented.
PT-2015-7490
7.5
2015-11-04
Mobatek · Mobaxterm · CVE-2015-7244
**Name of the Vulnerable Software and Affected Versions** MobaXterm versions prior to 8.3 **Description** The default configuration of the server in MobaXterm has a disabled Access Control setting, which does not require authentication for X11 connections. This allows remote attackers to execute arbitrary commands or obtain sensitive information via X11 packets. **Recommendations** For versions prior to 8.3, enable the Access Control setting to require authentication for X11 connections.