ZeroHour

CVE-2020-27985

PoC
CVSS 3.1
7.8 high
EPSS
<1%p43
Published
()
Modified
Description

Security Onion v2 prior to 2.3.10 has an incorrect sudo configuration, which allows the administrative user to obtain root access without using the sudo password by editing and executing /home/ /SecurityOnion/setup/so-setup.

Vendors
securityonionsolutions
Products
security onion
Weakness
CWE-306
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.