CVE Vulnerabilities

CVE-2023-41776

Improper Privilege Management

Published: Jan 03, 2024 | Modified: Jan 09, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

There is a local privilege escalation vulnerability of ZTEs ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to escalate local privileges.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Zxcloud_irai_firmware Zte * 7.23.32 (excluding)

Potential Mitigations

References