PT-2020-14869 · Rangeeos · Rangeeos
Published
2020-08-20
·
Updated
2020-08-24
·
CVE-2020-16282
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RangeeOS version 8.0.4
Description
The default configuration of RangeeOS executes all components in the context of the privileged root user, potentially allowing a local attacker to break out of the restricted environment or inject malicious code into the application, fully compromising the operating system.
Recommendations
For RangeeOS version 8.0.4, consider modifying the configuration to execute components with reduced privileges to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rangeeos