PT-2024-22289 · Image Access Gmbh · Scan2Net

Daniel Hirschberger

+1

·

Published

2024-12-11

·

Updated

2024-12-16

·

CVE-2024-28139

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned as affected, so the information cannot be consolidated into a specific format.
Description The issue allows the www-data user to elevate its privileges because sudo is configured to allow the execution of the mount command as root without a password. This configuration enables the privileges to be escalated to the root user. The vendor has accepted the risk, indicating that this issue will not be resolved in the near future.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-28139

Affected Products

Scan2Net