QID 376728
Date Published: 2022-07-19
QID 376728: MagniComp SysInfo Local Privilege Escalation Vulnerability
A local privileged root escalation vulnerability has been found and fixed in MagniComp's SysInfo product. The vulnerability allows local attackers to run local commands as root including the ability to run get a shell prompt as root.
Affected Versions:
SysInfo versions prior to 10-H64
QID Detection Logic (Authenticated):
The check matches Sysinfo version retrieved via Unix Auth using "/opt/sysinfo/bin/sysinfo -V" command.
This access could be exploited by a local attacker to gain a root shell prompt using the right combination of environment variables and command line arguments.
Solution
Upgrade to SysInfo 10-H64 or later
Vendor References
- CVE-2017-6516 -
www.magnicomp.com/support/cve/CVE-2017-6516.shtml
CVEs related to QID 376728
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 10-H64 |
|