CVE-2018-16497
Last modified
CVE-2018-16497 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server. If the job is run as the user root, there is a potential privilege escalation vulnerability. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server. If the job is run as the user root, there is a potential privilege escalation vulnerability. In this case, the job runs a script as root that is writable by users who are members of the versa group.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Versa-Networks | Versa Analytics | All versions |
References
- https://hackerone.com/reports/1168194Third Party Advisory
- https://hackerone.com/reports/1168194Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-16497?
How severe is CVE-2018-16497?
How do I fix CVE-2018-16497?
Are you affected by CVE-2018-16497?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
