#VU21160 Permissions, Privileges, and Access Controls in CUJO Smart Firewall - CVE-2018-3969

 

#VU21160 Permissions, Privileges, and Access Controls in CUJO Smart Firewall - CVE-2018-3969

Published: September 17, 2019


Vulnerability identifier: #VU21160
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: CVE-2018-3969
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
CUJO Smart Firewall
Software vendor:
CUJO AI

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insufficient permission restrictions in the verified boot protection. A local user who is able to write into "/config/dhcpd.conf" can add arbitrary shell commands into the "dhcpd.conf" file and execute arbitrary commands on the target system.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links