← Back

CVE-2018-18556

nvd nist
Published: Dec 17, 2018Modified: Nov 21, 2024

JSON object

Loading...
9.9
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.1 / Impact: 6.0
Source: NVD

Description

A privilege escalation issue was discovered in VyOS 1.1.8. The default configuration also allows operator users to execute the pppd binary with elevated (sudo) permissions. Certain input parameters are not properly validated. A malicious operator user can run the binary with elevated permissions and leverage its improper input validation condition to spawn an attacker-controlled shell with root privileges.

Affected (1)

Products: Vyos: Vyos
1 product
Vyos
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.1.8

Timeline

No history available yet.