CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:L/AC:L/Au:N/C:P/I:P/A:P
AI Score
Confidence
High
EPSS
Percentile
5.1%
Raritan Dominion SX (DSX) Console Servers DSX16, DSX32, DSX4, DSX8, and DSXA-48 set (1) world-readable permissions for /etc/shadow and (2) world-writable permissions for /bin/busybox, which allows local users to obtain hashed passwords or execute arbitrary code as other users.
Vendor | Product | Version | CPE |
---|---|---|---|
raritan | dominion_sx4_firmware | - | cpe:2.3:o:raritan:dominion_sx4_firmware:-:*:*:*:*:*:*:* |
raritan | dominion_sx4 | - | cpe:2.3:h:raritan:dominion_sx4:-:*:*:*:*:*:*:* |
raritan | dominion_sx8_firmware | - | cpe:2.3:o:raritan:dominion_sx8_firmware:-:*:*:*:*:*:*:* |
raritan | dominion_sx8 | - | cpe:2.3:h:raritan:dominion_sx8:-:*:*:*:*:*:*:* |
raritan | dominion_sx16_firmware | - | cpe:2.3:o:raritan:dominion_sx16_firmware:-:*:*:*:*:*:*:* |
raritan | dominion_sx16 | - | cpe:2.3:h:raritan:dominion_sx16:-:*:*:*:*:*:*:* |
raritan | dominion_sx32_firmware | 2.4.6 | cpe:2.3:o:raritan:dominion_sx32_firmware:2.4.6:*:*:*:*:*:*:* |
raritan | dominion_sx32 | - | cpe:2.3:h:raritan:dominion_sx32:-:*:*:*:*:*:*:* |
raritan | dominion_sxa-48_firmware | - | cpe:2.3:o:raritan:dominion_sxa-48_firmware:-:*:*:*:*:*:*:* |
raritan | dominion_sxa-48 | - | cpe:2.3:h:raritan:dominion_sxa-48:-:*:*:*:*:*:*:* |