漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenWrt luci-app-samba4 read ACL remote code execution via smbd
Vulnerability Description
OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments. Attackers can pass arbitrary Samba global options such as message command to a root smbd process, triggering command execution when SMB protocol messages are processed.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
特权管理不恰当
Vulnerability Title
OpenWRT luci 权限许可和访问控制问题漏洞
Vulnerability Description
OpenWRT luci是OpenWRT社区开源的一款路由器配置界面。 OpenWRT luci存在权限许可和访问控制问题漏洞,该漏洞源于luci-app-samba4的读ACL在/usr/sbin/smbd上授予file.exec权限,允许经过身份验证的委托用户通过调用者控制的命令行参数执行Samba守护程序,攻击者可将任意Samba全局选项(如消息命令)传递给root smbd进程,在处理SMB协议消息时触发命令执行。
CVSS Information
N/A
Vulnerability Type
N/A