Wind River VxWorks 7 的命令 shell 中存在一个不当的权限管理漏洞(CWE-269),该漏洞出现在配置了按用户执行命令权限控制的场景中。在某些 shell 操作下,某些命令可能绕过通常应用的权限检查而被执行,从而使拥有有限权限的已认证用户能够运行其未被授权执行的命令。成功利用该漏洞可能导致权限提升,进而影响受影响设备的机密性、完整性和可用性。该问题影响 VxWorks 7 26.09 之前的所有版本,并已在 26.09 版本中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Wind River Systems Inc | VxWorks 7 | VxWorks 7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Wind River Systems Inc | VxWorks 7 | VxWorks 7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet