Description
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows an attacker to escalate privileges to root. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.
Problem types
CWE-250 Execution with Unnecessary Privileges
Product status
*
Credits
Gjoko Krstic of Zero Science Lab
References
www.ilevia.com/
www.vulncheck.com/...ries/ilevia-eve-x1-server-root-priv-esc