CVE-2018-15332
—CVSS 3.0
7.0 high
EPSS
<1%p25
Published
()
Modified
Description
The svpn component of the F5 BIG-IP APM client prior to version 7.1.7.2 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host in a race condition.
- Vendors
- f5
- Products
- big-ip access policy manager, big-ip access policy manager client
- Weakness
- CWE-362
- Vector
- CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.