Description
Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system binaries with overly permissive file permissions. Several binaries executed by the root user are writable and executable by unprivileged local users. An attacker with local access can replace or modify these binaries to execute arbitrary commands with root privileges, enabling local privilege escalation.
Problem types
CWE-732 Incorrect Permission Assignment for Critical Resource
Product status
Any version
Credits
Victor A. Morales, Senior Pentester Team Leader, GM Sectec, Corp.
Omar Crespo, Pentester, GM Sectec, Corp.
VulnCheck
References
www.glory-global.com/
www.vulncheck.com/...scalation-via-insecure-file-permissions