[Forgot Password]
Login  Register Subscribe

24002

 
 

127027

 
 

102010

 
 

909

 
 

81374

 
 

133

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML view JSON

CVE-2017-15918Date: (C)2017-11-02   (M)2018-02-19


Sera 1.2 stores the user's login password in plain text in their home directory. This makes privilege escalation trivial and also exposes the user and system keychains to local attacks.

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score  : 7.8CVSS Score  : 2.1
Exploit Score: 1.8Exploit Score: 3.9
Impact Score : 5.9Impact Score : 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector: LOCAL
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: LOWAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: NONE
Confidentiality: HIGHAvailability: NONE
Integrity: HIGH 
Availability: HIGH 
  





Reference:
EXPLOIT-DB-43221
https://m4.rkw.io/blog/cve201715918-sera-12-local-root-privesc-and-password-disclosure.html

CWE    1
CWE-264

© 2013 SecPod Technologies