Vulnerability CVE-2013-5364


Published: 2014-01-25   Modified: 2014-01-26

Description:
Secunia CSI Agent 6.0.0.15017 and earlier, 6.0.1.1007 and earlier, and 7.0.0.21 and earlier, when running on Red Hat Linux, uses world-readable and world-writable permissions for /etc/csia_config.xml, which allows local users to change CSI Agent configuration by modifying this file.

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
3.6/10
4.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
None
Affected software
Secunia -> Csi agent 

 References:
http://www.securityfocus.com/bid/64775
https://exchange.xforce.ibmcloud.com/vulnerabilities/90230

Copyright 2024, cxsecurity.com

 

Back to Top