CVE-2021-29005
PoC —CVSS 3.1
8.8 high
EPSS
2%p81
Published
()
Modified
Description
Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute chmod as root without password which may let an attacker with low privilege to gain root access on server.
- Vendors
- rconfig
- Products
- rconfig
- Weakness
- CWE-276
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.