Vulnerability Details CVE-2016-2363
Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 uses weak permissions for the /var/www/rpc/surun script, which allows local users to obtain root access for unspecified command execution by leveraging access to the nobody account.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 10.6%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 7.2
Products affected by CVE-2016-2363
-
cpe:2.3:a:fonality:fonality:12.6
-
cpe:2.3:a:fonality:fonality:12.8
-
cpe:2.3:a:fonality:fonality:14.1i