← Back

CVE-2018-16494

nvd nist
Published: May 26, 2021Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

In VOS and overly permissive "umask" may allow for authorized users of the server to gain unauthorized access through insecure file permissions that can result in an arbitrary read, write, or execution of newly created files and directories. Insecure umask setting was present throughout the Versa servers.

Affected (3)

Versa Operating System
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Versa Networks
Before 16.1r2s11
From 20.2.0 to 20.2.2
From 21.1.0 to 21.1.1

References (2)

Source: support@hackerone.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.