Lucene search

K
cveZdiCVE-2024-30369
HistoryJun 06, 2024 - 6:15 p.m.

CVE-2024-30369

2024-06-0618:15:13
CWE-732
zdi
web.nvd.nist.gov
27
a10 thunder adc
privilege escalation
local attackers
incorrect permission
arbitrary code
zdi-can-22754

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

16.2%

A10 Thunder ADC Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of A10 Thunder ADC. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the installer. The issue results from incorrect permissions on a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-22754.

Affected configurations

Nvd
Vulners
Vulnrichment
Node
a10networksadvanced_core_operating_systemMatch4.1.4-
OR
a10networksadvanced_core_operating_systemMatch4.1.4gr1
OR
a10networksadvanced_core_operating_systemMatch4.1.4gr1-p1
OR
a10networksadvanced_core_operating_systemMatch4.1.4gr1-p10
OR
a10networksadvanced_core_operating_systemMatch4.1.4gr1-p11
OR
a10networksadvanced_core_operating_systemMatch4.1.4gr1-p12
OR
a10networksadvanced_core_operating_systemMatch4.1.4gr1-p13
OR
a10networksadvanced_core_operating_systemMatch4.1.4gr1-p2
OR
a10networksadvanced_core_operating_systemMatch4.1.4gr1-p3
OR
a10networksadvanced_core_operating_systemMatch4.1.4gr1-p4
OR
a10networksadvanced_core_operating_systemMatch4.1.4gr1-p5
OR
a10networksadvanced_core_operating_systemMatch4.1.4gr1-p6
OR
a10networksadvanced_core_operating_systemMatch4.1.4gr1-p7
OR
a10networksadvanced_core_operating_systemMatch4.1.4gr1-p8
OR
a10networksadvanced_core_operating_systemMatch4.1.4gr1-p9
OR
a10networksadvanced_core_operating_systemMatch4.1.4p1
OR
a10networksadvanced_core_operating_systemMatch4.1.4p2
OR
a10networksadvanced_core_operating_systemMatch4.1.4p3
Node
a10networksadvanced_core_operating_systemMatch5.1.0-
OR
a10networksadvanced_core_operating_systemMatch5.1.0p3
OR
a10networksadvanced_core_operating_systemMatch5.1.0p4
OR
a10networksadvanced_core_operating_systemMatch5.1.0p5
OR
a10networksadvanced_core_operating_systemMatch5.1.0p6
OR
a10networksadvanced_core_operating_systemMatch5.2.0-
OR
a10networksadvanced_core_operating_systemMatch5.2.0p1
OR
a10networksadvanced_core_operating_systemMatch5.2.1-
OR
a10networksadvanced_core_operating_systemMatch5.2.1p1
OR
a10networksadvanced_core_operating_systemMatch5.2.1p2
OR
a10networksadvanced_core_operating_systemMatch5.2.1p3
OR
a10networksadvanced_core_operating_systemMatch5.2.1p4
OR
a10networksadvanced_core_operating_systemMatch5.2.1p5
OR
a10networksadvanced_core_operating_systemMatch5.2.1p6
OR
a10networksadvanced_core_operating_systemMatch5.2.1p7
OR
a10networksadvanced_core_operating_systemMatch5.2.1p8
OR
a10networksadvanced_core_operating_systemMatch5.2.1p9
Node
a10networksadvanced_core_operating_systemMatch6.0.0-
OR
a10networksadvanced_core_operating_systemMatch6.0.0p1
OR
a10networksadvanced_core_operating_systemMatch6.0.0p2
OR
a10networksadvanced_core_operating_systemMatch6.0.0p2-sp1
OR
a10networksadvanced_core_operating_systemMatch6.0.1
OR
a10networksadvanced_core_operating_systemMatch6.0.2-
OR
a10networksadvanced_core_operating_systemMatch6.0.2p1
OR
a10networksadvanced_core_operating_systemMatch6.0.3-
VendorProductVersionCPE
a10networksadvanced_core_operating_system4.1.4cpe:2.3:o:a10networks:advanced_core_operating_system:4.1.4:-:*:*:*:*:*:*
a10networksadvanced_core_operating_system4.1.4cpe:2.3:o:a10networks:advanced_core_operating_system:4.1.4:gr1:*:*:*:*:*:*
a10networksadvanced_core_operating_system4.1.4cpe:2.3:o:a10networks:advanced_core_operating_system:4.1.4:gr1-p1:*:*:*:*:*:*
a10networksadvanced_core_operating_system4.1.4cpe:2.3:o:a10networks:advanced_core_operating_system:4.1.4:gr1-p10:*:*:*:*:*:*
a10networksadvanced_core_operating_system4.1.4cpe:2.3:o:a10networks:advanced_core_operating_system:4.1.4:gr1-p11:*:*:*:*:*:*
a10networksadvanced_core_operating_system4.1.4cpe:2.3:o:a10networks:advanced_core_operating_system:4.1.4:gr1-p12:*:*:*:*:*:*
a10networksadvanced_core_operating_system4.1.4cpe:2.3:o:a10networks:advanced_core_operating_system:4.1.4:gr1-p13:*:*:*:*:*:*
a10networksadvanced_core_operating_system4.1.4cpe:2.3:o:a10networks:advanced_core_operating_system:4.1.4:gr1-p2:*:*:*:*:*:*
a10networksadvanced_core_operating_system4.1.4cpe:2.3:o:a10networks:advanced_core_operating_system:4.1.4:gr1-p3:*:*:*:*:*:*
a10networksadvanced_core_operating_system4.1.4cpe:2.3:o:a10networks:advanced_core_operating_system:4.1.4:gr1-p4:*:*:*:*:*:*
Rows per page:
1-10 of 431

CNA Affected

[
  {
    "vendor": "A10",
    "product": "Thunder ADC",
    "versions": [
      {
        "version": "6.0.2, build 68",
        "status": "affected"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

16.2%

Related for CVE-2024-30369