Lucene search

K
nvd[email protected]NVD:CVE-2019-9971
HistoryJun 07, 2022 - 6:15 p.m.

CVE-2019-9971

2022-06-0718:15:10
CWE-269
web.nvd.nist.gov
4
cve-2019-9971
phonesystem terminal
debian based installation
root privileges
tcpdump command
postrotate-command option
sudo vulnerability

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.005

Percentile

77.9%

PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo with the tcpdump command, without a password. This occurs because the -z (aka postrotate-command) option to tcpdump can be unsafe when used in conjunction with sudo.

Affected configurations

Nvd
Node
3cxphone_system_firmwareMatch16.0.0.1570
AND
3cxphone_systemMatch-
Node
debiandebian_linuxMatch-
VendorProductVersionCPE
3cxphone_system_firmware16.0.0.1570cpe:2.3:o:3cx:phone_system_firmware:16.0.0.1570:*:*:*:*:*:*:*
3cxphone_system-cpe:2.3:h:3cx:phone_system:-:*:*:*:*:*:*:*
debiandebian_linux-cpe:2.3:o:debian:debian_linux:-:*:*:*:*:*:*:*

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.005

Percentile

77.9%

Related for NVD:CVE-2019-9971