PT-2022-23764 · Grommunio · Gromox

Filippo Bonazzi

·

Published

2022-08-04

·

Updated

2022-08-10

·

CVE-2022-37030

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grommunio Gromox versions 0.5 through 1.x before 1.28
Description The issue is related to weak permissions on the configuration file in the PAM module, allowing a local unprivileged user in the gromox group to execute arbitrary code upon loading the Gromox PAM module.
Recommendations For versions 0.5 through 1.x before 1.28, update to version 1.28 or later to resolve the issue.

Exploit

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2022-37030

Affected Products

Gromox