ZeroHour

CVE-2021-29005

PoC
CVSS 3.1
8.8 high
EPSS
2%p81
Published
()
Modified
Description

Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute chmod as root without password which may let an attacker with low privilege to gain root access on server.

Vendors
rconfig
Products
rconfig
Weakness
CWE-276
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.