#VU21160 Permissions, Privileges, and Access Controls in CUJO Smart Firewall - CVE-2018-3969
Published: September 17, 2019
CUJO Smart Firewall
CUJO AI
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insufficient permission restrictions in the verified boot protection. A local user who is able to write into "/config/dhcpd.conf" can add arbitrary shell commands into the "dhcpd.conf" file and execute arbitrary commands on the target system.