vendor:
Cyclades Serial Console Server
by:
@ibby
7.2
CVSS
HIGH
Local Privilege Escalation
269
CWE
Product Name: Cyclades Serial Console Server
Affected Version From: V_1.0.0
Affected Version To: V_3.3.0-16
Patch Exists: NO
Related CWE:
CPE: a:vertiv:cyclades_serial_console_server
Platforms Tested: Legacy Versions V_1.0.0 to V_3.3.0-16
2022
Cyclades Serial Console Server 3.3.0 – Local Privilege Escalation
The software ships with overly permissive sudo privileges for any user in the admin group, or the default admin user. This vulnerability exists in all legacy versions of the software - the last version being from ~2014. This vulnerability does not exist in the newer distributions of the ACS Software.
Mitigation:
The user should ensure that the sudo privileges are not overly permissive and should be restricted to only the necessary commands.