CVE Vulnerabilities

CVE-2022-29594

Improper Preservation of Permissions

Published: Jun 02, 2022 | Modified: Jun 13, 2022
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM.

Weakness

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Affected Software

Name Vendor Start Version End Version
Eg_agent Eginnovations * 7.1.11 (including)
Eg_manager Eginnovations * 7.1.8 (including)
Eg_rum_collectors Eginnovations 7.1.0 (including) 7.2 (excluding)
Vm_agent Eginnovations * 7.1.8 (including)

References