CVE-2018-16494 Vulnerability Details

  /     /     /  

CVE-2018-16494 Metadata Quick Info

CVE Published: 26/05/2021 | CVE Updated: 05/08/2024 | CVE Year: 2018
Source: hackerone | Vendor: n/a | Product: Versa VOS
Status : PUBLISHED

CVE-2018-16494 Description

In VOS and overly permissive "umask" may allow for authorized users of the server to gain unauthorized access through insecure file permissions that can result in an arbitrary read, write, or execution of newly created files and directories. Insecure umask setting was present throughout the Versa servers.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-377
CWE Name: Insecure Temporary File (CWE-377)
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).