NitroSecurity NitroView Enterprise Security Manager (ESM) Local Privilege Escalation Vulnerability
BID:43295
Info
NitroSecurity NitroView Enterprise Security Manager (ESM) Local Privilege Escalation Vulnerability
| Bugtraq ID: | 43295 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 17 2010 12:00AM |
| Updated: | Sep 17 2010 12:00AM |
| Credit: | Ben Nell of Foreground Security |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
NitroSecurity NitroView Enterprise Security Manager (ESM) Local Privilege Escalation Vulnerability
NitroView Enterprise Security Manager (ESM) is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to read arbitrary local files on the vulnerable system and gain elevated privileges. Other attacks may also be possible.
NitroView Enterprise Security Manager (ESM) firmware version 8.4.0 is vulnerable; other versions may also be affected.
NitroView Enterprise Security Manager (ESM) is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to read arbitrary local files on the vulnerable system and gain elevated privileges. Other attacks may also be possible.
NitroView Enterprise Security Manager (ESM) firmware version 8.4.0 is vulnerable; other versions may also be affected.
References
NitroSecurity NitroView Enterprise Security Manager (ESM) Local Privilege Escalation Vulnerability
References:
References:
- NitroSecurity Homepage (NitroSecurity)
- NitroView Enterprise Security Manager (ESM) Product Page (NitroSecurity)