Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-11053


Dell EMC iDRAC Service Module for all supported Linux and XenServer versions v3.0.1, v3.0.2, v3.1.0, v3.2.0, when started, changes the default file permission of the hosts file of the host operating system (/etc/hosts) to world writable. A malicious low privileged operating system user or process could modify the host file and potentially redirect traffic from the intended destination to sites hosting malicious or unwanted content.


Published

2018-06-26T22:29:00.210

Last Modified

2024-11-21T03:42:34.380

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-732

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell emc_idrac_service_module 3.0.1 Yes
Application dell emc_idrac_service_module 3.0.2 Yes
Application dell emc_idrac_service_module 3.1.0 Yes
Application dell emc_idrac_service_module 3.2.0 Yes
Application citrix xenserver 7.1 No
Operating System redhat enterprise_linux 6.9 No
Operating System redhat enterprise_linux 7.4 No
Operating System suse suse_linux_enterprise_server 11 No
Operating System suse suse_linux_enterprise_server 12 No

References