Description

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning sudo privileges, C-MOR is vulnerable to a privilege escalation attack. The Linux user www-data running the C-MOR web interface can execute some OS commands as root via Sudo without having to enter the root password. These commands, for example, include cp, chown, and chmod, which enable an attacker to modify the system's sudoers file in order to execute all commands with root privileges. Thus, it is possible to escalate the limited privileges of the user www-data to root privileges.

INFO

Published Date :

2024-09-05T00:00:00.000Z

Last Modified :

2024-09-06T06:03:37.222Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-45173 vulnerability.

Vendors Products
C-mor
  • C-mor Video Surveillance
Za-internet
  • C-mor Video Surveillance

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact