vendor:
xglance-bin
by:
Robert Jaroszuk and Marco Ortisi
7.5
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: xglance-bin
Affected Version From: 11
Affected Version To: 11
Patch Exists: NO
Related CWE: CVE-2014-2630
CPE: a:hewlett-packard:xglance-bin:11.00
Platforms Tested: RHEL 5.x/6.x/7.x/8.x
2020
xglance-bin 11.00 – Privilege Escalation
This exploit allows an attacker to escalate their privileges in the xglance-bin 11.00 software. It leverages a vulnerability with CVE-2014-2630. The exploit code sets the user ID to the effective user ID, and then executes a shell command.
Mitigation:
Apply the latest patches and updates for the xglance-bin software to fix the privilege escalation vulnerability.