#VU25404 Permissions, Privileges, and Access Controls in Vantage Velocity - CVE-2020-9024
Published: February 17, 2020
Vantage Velocity
Iteris, Inc.
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the affected devices have world-writable permissions for the "/root/cleardata.pl "
(executed as root by crond) and "/root/loadperl.sh" (executed as root at
boot time) scripts. A remote attacker can gain elevated privileges on the target system.