CVE-2020-27985
23.11.2020, 14:15
Security Onion v2 prior to 2.3.10 has an incorrect sudo configuration, which allows the administrative user to obtain root access without using the sudo password by editing and executing /home/<user>/SecurityOnion/setup/so-setup.Enginsight
Vendor | Product | Version |
---|---|---|
securityonionsolutions | security_onion | 2.0.0 ≤ 𝑥 < 2.3.10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References