CVE-2021-45809

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/03/2022
Last modified:
19/10/2022

Description

GlobalProtect-openconnect versions prior to 1.4.3 are affected by incorrect access control in GPService through DBUS, GUI Application. The way GlobalProtect-Openconnect is set up enables arbitrary users to execute commands as root by submitting the `--script=` parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:globalprotect-openconnect_project:globalprotect-openconnect:*:*:*:*:*:*:*:* 1.4.3 (excluding)


References to Advisories, Solutions, and Tools