PT-2018-14513 · Vyos · Vyos
Rich Mirch
·
Publicado
2018-12-17
·
Atualizado
2019-10-03
·
CVE-2018-18555
CVSS v3.1
9.9
Crítica
| Vetor | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
VyOS version 1.1.8
Description
A sandbox escape issue was discovered, allowing an authenticated operator user to break out of the restricted management shell by issuing certain shell special characters with commands. This enables the user to gain access to the underlying Linux shell and run arbitrary operating system commands with their account privileges.
Recommendations
For VyOS version 1.1.8, consider restricting access to the management shell until a patch is available, and limit the use of shell special characters in commands to minimize the risk of exploitation.
Exploit
Correção
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Vyos