CVE-2018-10900
Network Manager VPNC 1.2.6 - 'Username' Local Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.
El plugin VPNC de Network Manager (también conocido como networkkmanager-vpnc) en versiones anteriores a la 1.2.6 es vulnerable a un ataque de escalado de privilegios. Un nuevo carácter de línea puede ser usado para inyectar un parámetro Password helper en los datos de configuración pasados a VPNC, permitiendo al atacante ejecutar comandos arbitrarios como root.
Network Manager VPNC version 1.2.4 suffers from a privilege escalation vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-05-09 CVE Reserved
- 2018-07-23 CVE Published
- 2023-07-20 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (14)
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/45313 | 2024-08-05 | |
https://bugzilla.novell.com/show_bug.cgi?id=1101147 | 2024-08-05 | |
https://pulsesecurity.co.nz/advisories/NM-VPNC-Privesc | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10900 | 2020-12-04 | |
https://gitlab.gnome.org/GNOME/NetworkManager-vpnc/commit/07ac18a32b4 | 2018-07-26 |
URL | Date | SRC |
---|---|---|
https://download.gnome.org/sources/NetworkManager-vpnc/1.2/NetworkManager-vpnc-1.2.6.news | 2020-12-04 | |
https://security.gentoo.org/glsa/201808-03 | 2020-12-04 | |
https://www.debian.org/security/2018/dsa-4253 | 2018-07-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gnome Search vendor "Gnome" | Network Manager Vpnc Search vendor "Gnome" for product "Network Manager Vpnc" | < 1.2.6 Search vendor "Gnome" for product "Network Manager Vpnc" and version " < 1.2.6" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|