A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3.10 allows local users arbitrary code execution as root. Redhat-based systems using RPM packages are not affected.
2025-04-11T13:15:40.097
2025-05-07T16:34:40.470
Analyzed
CVSSv3.1: 7.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sophos | taegis_endpoint_agent | < 1.3.10 | Yes |
Operating System | debian | debian_linux | - | No |