Accellion Kiteworks appliances before kw2016.03.00 use setuid-root permissions for /opt/bin/cli, which allows local users to gain privileges via unspecified vectors.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Kiteworks_appliance |
Accellion |
* |
kw2016.03.00 (including) |
References