PT-2024-31457 · Za Internet · Za-Internet C-Mor Video Surveillance

Chris Beiter

+2

·

Published

2024-09-05

·

Updated

2025-09-04

·

CVE-2024-45173

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions za-internet C-MOR Video Surveillance version 5.2401
Description An issue was discovered due to improper privilege management concerning sudo privileges, making C-MOR vulnerable to a privilege escalation attack. The Linux user www-data running the C-MOR web interface can execute some OS commands as root via Sudo without having to enter the root password. These commands include cp, chown, and chmod, which enable an attacker to modify the system's sudoers file in order to execute all commands with root privileges. Thus, it is possible to escalate the limited privileges of the user www-data to root privileges.
Recommendations For version 5.2401, consider restricting the sudo privileges of the www-data user to prevent the execution of sensitive commands like cp, chown, and chmod until a patch is available. As a temporary workaround, consider disabling the sudo access for the www-data user to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-45173

Affected Products

Za-Internet C-Mor Video Surveillance