CVE-2022-48685
CVSS 3.1 Score 7.7 of 10 (high)
Details
Published Apr 27, 2024
Updated: Jul 3, 2024
CWE ID 276
Summary
CVE-2022-48685 is a privilege escalation vulnerability affecting Logpoint 7.1 versions prior to 7.1.2. The issue lies in a daily cron file named clean_secbi_old_logs, which is executable as root but is writable by all users. This misconfiguration allows unauthorized users to modify the file and potentially gain root access, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share