MagniComp SysInfo 10-H62

CPE Details

MagniComp SysInfo 10-H62
10-h62
2020-01-23
14h52 +00:00
2020-01-23
14h52 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:magnicomp:sysinfo:10-h62:*:*:*:*:*:*:*

Informations

Vendor

magnicomp

Product

sysinfo

Version

10-h62

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2018-7268 2018-05-21 13h00 +00:00 MagniComp SysInfo before 10-H81, as shipped with BMC BladeLogic Automation and other products, contains an information exposure vulnerability in which a local unprivileged user is able to read any root (uid 0) owned file on the system, regardless of the file permissions. Confidential information such as password hashes (/etc/shadow) or other secrets (such as log files or private keys) can be leaked to the attacker. The vulnerability has a confidentiality impact, but has no direct impact on system integrity or availability.
5.5
Medium
CVE-2017-6516 2017-03-14 16h00 +00:00 A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow a local attacker to gain elevated privileges. Parts of SysInfo require setuid-to-root access in order to access restricted system files and make restricted kernel calls. This access could be exploited by a local attacker to gain a root shell prompt using the right combination of environment variables and command line arguments.
6.7
Medium