CVE-2006-4316: High severity SSH Tectia Manager vulnerability
SSH Tectia Management Agent 2.1.2 allows local users to gain root privileges by running a program called sshd, which is obtained from a process listing when the "Restart" action is selected from the Management server GUI, which causes the agent to locate the pathname of the user's program and restart it with root privileges.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4316?
CVE-2006-4316 has a high severity rating due to the potential for local users to gain root privileges.
How do I fix CVE-2006-4316?
To fix CVE-2006-4316, upgrade to a version of SSH Tectia Manager that is not vulnerable, specifically any version after 2.1.2.
What versions of SSH Tectia Manager are affected by CVE-2006-4316?
CVE-2006-4316 affects SSH Tectia Manager versions 1.2, 1.3, 1.4, 2.0, and 2.1.2.
What does CVE-2006-4316 exploit?
CVE-2006-4316 exploits a flaw that allows local users to execute a program called sshd for privilege escalation.
Is there a known exploit for CVE-2006-4316?
Yes, CVE-2006-4316 has been documented to allow local users to exploit the default functioning of the SSH Tectia Management Agent.