Weak Permissions in Cryoserver Security Appliance 7.3.x Allow Local Privilege Escalation

Weak Permissions in Cryoserver Security Appliance 7.3.x Allow Local Privilege Escalation

CVE-2014-4867 · MEDIUM Severity

AV:L/AC:L/AU:S/C:C/I:C/A:C

Cryoserver Security Appliance 7.3.x uses weak permissions for /etc/init.d/cryoserver, which allows local users to gain privileges by leveraging access to the support account and running the /bin/cryo-mgmt program.

Learn more about our Cis Benchmark Audit For Server Software.