Fidelissecurity

Deception

13 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 17.05.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:38:45

Improper file permissions in the CommandPost, Collector, Sensor, and Sandbox components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected files and enable escalation of privileges equ...

  • EPSS 0.53%
  • Veröffentlicht 17.05.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:39:49

Improper file permissions in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected script files, which could result in arbitrary commands...

  • EPSS 0.87%
  • Veröffentlicht 17.05.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:50:19

Vulnerability in rconfig “date” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as well as neighboring Fidelis components. T...

  • EPSS 0.87%
  • Veröffentlicht 17.05.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:50:19

Vulnerability in rconfig “cert_utils” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as well as neighboring Fidelis compone...

  • EPSS 0.82%
  • Veröffentlicht 17.05.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:50:19

Vulnerability in rconfig “remote_text_file” enables an attacker with user level access to the CLI to inject user level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as well as neighboring Fidelis c...

  • EPSS 0.61%
  • Veröffentlicht 17.05.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:50:19

Vulnerability in Fidelis Network and Deception CommandPost enables SQL injection through the web interface by an attacker with user level access. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updat...

  • EPSS 0.71%
  • Veröffentlicht 17.05.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:50:19

Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “feed_comm_test” value for the “feed” parameter. The vulnerability could allow a specially crafted HTTP request to ...

  • EPSS 0.71%
  • Veröffentlicht 17.05.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:50:19

Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “check_vertica_upgrade” value for the “cpIp” parameter. The vulnerability could allow a specially crafted HTTP requ...

  • EPSS 0.71%
  • Veröffentlicht 17.05.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:50:19

Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “update_checkfile” value for the “filename” parameter. The vulnerability could allow a specially crafted HTTP reque...

Exploit
  • EPSS 0.89%
  • Veröffentlicht 25.06.2021 12:15:08
  • Zuletzt bearbeitet 21.11.2024 06:11:44

Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the CLI to inject root level commands into the component and neighboring Fidelis components. The vulnera...