PT-2021-14394 · Traccar · Traccar
Lowtananaev
·
Published
2021-02-02
·
Updated
2021-02-08
·
CVE-2021-21292
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Traccar versions prior to 4.12
Description:
Traccar is an open source GPS tracking system. The issue is an unquoted Windows binary path vulnerability, which impacts only Windows versions. An attacker needs write access to the filesystem on the host machine to exploit this. If the Java path includes a space, the attacker can elevate their privilege to the same level as the Traccar service, which is system-level.
Recommendations:
For versions prior to 4.12, update to version 4.12 to resolve the issue. As a temporary workaround, consider restricting write access to the filesystem on the host machine to minimize the risk of exploitation. Additionally, ensure the Java path does not include any spaces to prevent privilege elevation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Traccar