Advisories

Cyclades Serial Console Server 3.3.0 - Local Privilege Escalation

Go Back
severity
high
date
Affecting
  • Cyclades Serial Console Server 1.0.0 - 3.3.0

CWE
  • CWE-266 Incorrect Privilege Assignment
CVSS
8.5
CVSS V4 Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
Cyclades Serial Console Server 3.3.0 contains a local privilege escalation vulnerability due to overly permissive sudo privileges for the admin user and admin group. Attackers can exploit the default user configuration to gain root access by manipulating system binaries and leveraging unrestricted sudo permissions.