A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The affected devices contain a SUID binary that could allow an authenticated local attacker to execute arbitrary commands with root privileges.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://cert-portal.siemens.com/productcert/html/ssa-333468.html | vendor advisory |