ZeroHour

CVE-2018-16494

CVSS 3.1
8.8 high
EPSS
2%p79
Published
()
Modified
Description

In VOS and overly permissive "umask" may allow for authorized users of the server to gain unauthorized access through insecure file permissions that can result in an arbitrary read, write, or execution of newly created files and directories. Insecure umask setting was present throughout the Versa servers.

Vendors
versa-networks
Products
versa operating system
Weakness
CWE-377, CWE-668
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.