Description
Sangfor aTrust through 2.4.10 allows users to modify the ExecStartPre command.
Problem types
CWE-732 Incorrect Permission Assignment for Critical Resource
Product status
2.4.10
References
github.com/r00t7oo2jm/cVetest/blob/main/p0c.sh
github.com/r00t7oo2jm/cVetest/blob/main/sangf0r-poc.pdf
marketplace.huaweicloud.com/...f-57b5-4780-9c0c-58af8f7f71e6
community.sangfor.com/forum.php?mod=viewthread&tid=10842