Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inject arbitrary commands to /installers/common.sh component that can result in remote command execution with root privileges.
References
Configurations
History
21 Nov 2024, 06:08
Type | Values Removed | Values Added |
---|---|---|
References | () https://gist.github.com/omriinbar/52c000c02a6992c6ce68d531195f69cf - Third Party Advisory | |
References | () https://github.com/RaspAP/raspap-webgui/blob/5a7b77459839c9420fac0d10ec28cee1af9bb782/installers/common.sh#L216 - Exploit, Third Party Advisory | |
References | () https://github.com/RaspAP/raspap-webgui/blob/5a7b77459839c9420fac0d10ec28cee1af9bb782/installers/common.sh#L231 - Exploit, Third Party Advisory | |
References | () https://github.com/RaspAP/raspap-webgui/blob/5a7b77459839c9420fac0d10ec28cee1af9bb782/installers/common.sh#L314 - Exploit, Third Party Advisory | |
References | () https://github.com/RaspAP/raspap-webgui/blob/5a7b77459839c9420fac0d10ec28cee1af9bb782/installers/common.sh#L407 - Exploit, Third Party Advisory | |
References | () https://github.com/RaspAP/raspap-webgui/blob/5a7b77459839c9420fac0d10ec28cee1af9bb782/installers/common.sh#L510 - Exploit, Third Party Advisory |
21 Jun 2021, 16:11
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 9.0
v3 : 8.8 |
References | (MISC) https://gist.github.com/omriinbar/52c000c02a6992c6ce68d531195f69cf - Third Party Advisory | |
References | (MISC) https://github.com/RaspAP/raspap-webgui/blob/5a7b77459839c9420fac0d10ec28cee1af9bb782/installers/common.sh#L510 - Exploit, Third Party Advisory | |
References | (MISC) https://github.com/RaspAP/raspap-webgui/blob/5a7b77459839c9420fac0d10ec28cee1af9bb782/installers/common.sh#L231 - Exploit, Third Party Advisory | |
References | (MISC) https://github.com/RaspAP/raspap-webgui/blob/5a7b77459839c9420fac0d10ec28cee1af9bb782/installers/common.sh#L216 - Exploit, Third Party Advisory | |
References | (MISC) https://github.com/RaspAP/raspap-webgui/blob/5a7b77459839c9420fac0d10ec28cee1af9bb782/installers/common.sh#L314 - Exploit, Third Party Advisory | |
References | (MISC) https://github.com/RaspAP/raspap-webgui/blob/5a7b77459839c9420fac0d10ec28cee1af9bb782/installers/common.sh#L407 - Exploit, Third Party Advisory | |
CWE | CWE-269 | |
CPE | cpe:2.3:a:raspap:raspap:*:*:*:*:*:*:*:* |
09 Jun 2021, 19:22
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-06-09 18:15
Updated : 2024-11-21 06:08
NVD link : CVE-2021-33356
Mitre link : CVE-2021-33356
CVE.ORG link : CVE-2021-33356
JSON object : View
Products Affected
raspap
- raspap
CWE
CWE-269
Improper Privilege Management