CVE Vulnerabilities

CVE-2024-41903

Improper Privilege Management

Published: Aug 13, 2024 | Modified: Aug 14, 2024
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application mounts the containers root filesystem with read and write privileges. This could allow an attacker to alter the containers filesystem leading to unauthorized modifications and data corruption.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Sinec_traffic_analyzer Siemens * 2.0 (excluding)

Potential Mitigations

References