Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-37704

Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 27.8%
CVSS Severity
CVSS v3 Score 6.7
References
Products affected by CVE-2022-37704
  • Zmanda » Amanda » Version: 3.5.1
    cpe:2.3:a:zmanda:amanda:3.5.1


Contact Us

Shodan ® - All rights reserved