Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Bryan Rhodes

#17484of 53,633
15.3Total CVSS
Vulnerabilities · 2
High
2
PT-2019-9974
7.8
2019-04-25
Cerner · Cerner Connectivity Engine · CVE-2018-20052
**Name of the Vulnerable Software and Affected Versions** Cerner Connectivity Engine (CCE) version 4 **Description** An issue was discovered where the user running the main CCE firmware has NOPASSWD sudo privileges to several utilities, which could be used to escalate privileges to root. For example, the command "sudo ln -s /tmp/script /etc/cron.hourly/script" could be utilized. **Recommendations** For Cerner Connectivity Engine (CCE) version 4, restrict the sudo privileges of the user running the main CCE firmware to prevent escalation to root. As a temporary workaround, consider disabling the use of sudo for the affected utilities until a more permanent solution is implemented.
PT-2015-7490
7.5
2015-11-04
Mobatek · Mobaxterm · CVE-2015-7244
**Name of the Vulnerable Software and Affected Versions** MobaXterm versions prior to 8.3 **Description** The default configuration of the server in MobaXterm has a disabled Access Control setting, which does not require authentication for X11 connections. This allows remote attackers to execute arbitrary commands or obtain sensitive information via X11 packets. **Recommendations** For versions prior to 8.3, enable the Access Control setting to require authentication for X11 connections.