PT-2021-14949 · Huawei · Manageone
Published
2021-03-22
·
Updated
2021-03-24
·
CVE-2021-22311
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
ManageOne versions 8.0.0, 8.0.1
Description:
The issue is related to an improper permission assignment in the Huawei ManageOne product. This is due to improper security hardening, allowing a process to run with higher privileges than intended. As a result, certain users may be able to perform operations with improper permissions.
Recommendations:
For ManageOne versions 8.0.0 and 8.0.1, update to a version that includes proper security hardening to prevent the process from running with elevated privileges.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Manageone