Cisco ThousandEyes Enterprise Agent Virtual Appliance Arbitrary File Modification

Discussion in 'News Aggregator' started by Packet Storm, 19 Aug 2023.

  1. Packet Storm

    Packet Storm Guest

    Cisco ThousandEyes Enterprise Agent Virtual Appliance version thousandeyes-va-64-18.04 0.218 suffers from an unpatched vulnerability in sudoedit, allowed by sudo configuration, which permits a low-privilege user to modify arbitrary files as root and subsequently execute arbitrary commands as root.

    Continue reading...
     

Share This Page

Loading...