Security Advisory

CVE-2023-40361

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-10-20 00:00:00
Last updated 2024-09-12 17:52:56
Assigner mitre
State PUBLISHED

Description

SECUDOS Qiata (DOMOS OS) 4.13 has Insecure Permissions for the previewRm.sh daily cronjob. To exploit this, an attacker needs access as a low-privileged user to the underlying DOMOS system. Every user on the system has write permission for previewRm.sh, which is executed by the root user.