CVE-2014-4867

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
10/10/2014
Last modified:
12/04/2025

Description

Cryoserver Security Appliance 7.3.x uses weak permissions for /etc/init.d/cryoserver, which allows local users to gain privileges by leveraging access to the support account and running the /bin/cryo-mgmt program.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cryoserver:cryoserver_security_appliance:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:cryoserver:cryoserver_security_appliance:7.3.0:a:*:*:*:*:*:*
cpe:2.3:a:cryoserver:cryoserver_security_appliance:7.3.1:*:*:*:*:*:*:*
cpe:2.3:a:cryoserver:cryoserver_security_appliance:7.3.1:a:*:*:*:*:*:*
cpe:2.3:a:cryoserver:cryoserver_security_appliance:7.3.2:*:*:*:*:*:*:*
cpe:2.3:a:cryoserver:cryoserver_security_appliance:7.3.3:*:*:*:*:*:*:*
cpe:2.3:a:cryoserver:cryoserver_security_appliance:7.3.4:*:*:*:*:*:*:*