漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
`/bin/date` Binary given SETUID Permissions on IDC SFX2100 Leading to Potential LPE
Vulnerability Description
International Data Casting (IDC) SFX2100 satellite receiver comes with the `/bin/date` utility installed with the setuid bit set. This configuration grants elevated privileges to any local user who can execute the binary. A local actor is able to use the GTFObins resource to preform privileged file reads as the root user on the local file system. This allows an actor to be able to read any root read-only files, such as the /etc/shadow file or other configuration/secrets carrier files.
CVSS Information
N/A
Vulnerability Type
特权管理不恰当
Vulnerability Title
International Datacasting SFX2100 SuperFlex Satellite Receiver 安全漏洞
Vulnerability Description
International Datacasting SFX2100 SuperFlex Satellite Receiver是美国International Datacasting公司的一个专业广播级卫星信号接收设备。 International Datacasting SFX2100 SuperFlex Satellite Receiver存在安全漏洞,该漏洞源于/bin/date实用程序设置了setuid位,可能导致本地用户读取根用户只读文件。
CVSS Information
N/A
Vulnerability Type
N/A