8.8
CVSSv3

CVE-2018-15767

Published: 30/11/2018 Updated: 03/10/2019
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 905
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

The Dell OpenManage Network Manager virtual appliance versions before 6.5.3 contain an improper authorization vulnerability caused by a misconfiguration in the /etc/sudoers file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dell openmanage network manager

Exploits

''' KL-001-2018-009 : Dell OpenManage Network Manager Multiple Vulnerabilities Title: Dell OpenManage Network Manager Multiple Vulnerabilities Advisory ID: KL-001-2018-009 Publication Date: 20181105 Publication URL: wwwkorelogiccom/Resources/Advisories/KL-001-2018-009txt 1 Vulnerability Details Affected Vendor: Dell Affe ...
Dell OpenManage Network Manager exposes a MySQL listener that can be accessed with default credentials This MySQL service is running as the root user, so an attacker can exploit this configuration to, eg, deploy a backdoor and escalate privileges into the root account ...