PT-2022-3531 · Apache · Apache Web Server

Anthony Candarini

+3

·

Published

2022-06-23

·

Updated

2022-07-06

·

CVE-2022-2104

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SEPCOS Single Package versions (affected versions not specified)
Description The issue is related to insecure privilege management in the SEPCOS Single Package software. It allows a remote attacker to elevate their privileges. The www-data account, used by the Apache web server, is configured to run sudo with no password for many commands, including /bin/sh and /bin/bash.
Recommendations For SEPCOS Single Package, restrict the use of the sudo command for the www-data account to minimize the risk of exploitation. As a temporary workaround, consider disabling the ability of the www-data account to run commands like /bin/sh and /bin/bash until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04314
CVE-2022-2104

Affected Products

Apache Web Server