PoC Index

CVE-2020-15850

HIGH 7.8EPSS 0.5%

Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access the Nakivo Director web interface and gain root privileges. This occurs because the database containing the users of the web application and the password-recovery secret value is readable.

CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
0.52% chance of exploitation in the next 30 days, 42th percentile
Published
2020-09-24
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related