← back
CVE-2018-15767

Improper Authorization Vulnerability

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 12%
from disclosure to weapon0 days
Published on NVDNov 30
1st PoCNov 14
exploitation probability
12%top 4% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
In short

Dell OpenManage Network Manager versions before 6.5.3 have a security misconfiguration that allows users to perform actions they shouldn't be able to perform due to incorrect permission settings in the system file that controls administrative privileges.

Technical detail

An improper authorization vulnerability exists in Dell OpenManage Network Manager virtual appliance versions prior to 6.5.3 due to misconfiguration in the /etc/sudoers file, allowing local users to escalate privileges and execute commands with elevated permissions beyond their intended authorization level.

Summary generated and translated by AI from the official description.
The Dell OpenManage Network Manager virtual appliance versions prior to 6.5.3 contain an improper authorization vulnerability caused by a misconfiguration in the /etc/sudoers file.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.