WANem v2.3 Unauthorized Remote Root Access

Strike ID:
E12-95h01
CVSS:
10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
4
Year:
2012

Description

This strike exploits the Wide Area Network Emulator WANem. By combining a privelage escalation vulnerability with the dosu binary file as setuid root that executes commands supplied as its argument with the ability to inject commands into the pc parameter remotely, a user is able to gain root access remotely.

References

Bid