CVE-2018-7268: Infoleak
MagniComp SysInfo before 10-H81, as shipped with BMC BladeLogic Automation and other products, contains an information exposure vulnerability in which a local unprivileged user is able to read any root (uid 0) owned file on the system, regardless of the file permissions. Confidential information such as password hashes (/etc/shadow) or other secrets (such as log files or private keys) can be leaked to the attacker. The vulnerability has a confidentiality impact, but has no direct impact on system integrity or availability.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs local access to the affected system and only unprivileged user permissions. No user interaction is required.
What information could be exposed?
The issue allows reading files owned by root regardless of their permissions. Examples include password hashes in /etc/shadow, log files, private keys, and other secrets.
Does this vulnerability let an attacker modify files or disrupt the system?
No direct integrity or availability impact is described. The stated impact is disclosure of confidential information.
Which installations are affected?
MagniComp SysInfo versions before 10-H81 are affected, including versions shipped with BMC BladeLogic Automation and other products.