7.8
CVE-2018-11063
- EPSS 0.05%
- Veröffentlicht 10.08.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:36
- Quelle security_alert@emc.com
- CVE-Watchlists
- Unerledigt
Dell WMS versions 1.1 and prior are impacted by multiple unquoted service path vulnerabilities. Affected software installs multiple services incorrectly by specifying the paths to the service executables without quotes. This could potentially allow a low-privileged local user to execute arbitrary executables with elevated privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Wyse Management Suite SwEditionpro Version <= 1.1
Dell ≫ Wyse Management Suite SwEditionstandard Version <= 1.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.127 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-428 Unquoted Search Path or Element
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.