Innominate mGuard with firmware before 7.6.6 and 8.x before 8.1.4 allows remote authenticated admins to obtain root privileges by changing a PPP configuration setting.
Solution:
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.innominate.com/data/downloads/software/innominate_security_advisory_20141217_001_en.pdf | vendor advisory |
https://www.cisa.gov/news-events/ics-advisories/icsa-14-352-02 | |
https://ics-cert.us-cert.gov/advisories/ICSA-14-352-02 | third party advisory us government resource |