CVE-2020-28046: High severity pax prolinos vulnerability
An issue was discovered in ProlinOS through 2.4.161.8859R. An attacker with local code execution privileges as a normal user (MAINAPP) can escalate to root privileges by exploiting the setuid installation of the xtables-multi binary and leveraging the ip6tables --modprobe switch.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-28046?
CVE-2020-28046 is considered a critical vulnerability due to the potential for local privilege escalation from a normal user to root.
How do I fix CVE-2020-28046?
To mitigate CVE-2020-28046, you should update ProlinOS to a version beyond 2.4.161.8859R or remove the setuid permission from the xtables-multi binary.
Who is affected by CVE-2020-28046?
CVE-2020-28046 affects users of ProlinOS versions up to and including 2.4.161.8859R who have local code execution privileges.
What type of attack can be executed using CVE-2020-28046?
An attacker can exploit CVE-2020-28046 to achieve root privilege escalation by leveraging the vulnerable setuid installation of the xtables-multi binary.
Is CVE-2020-28046 a remote vulnerability?
CVE-2020-28046 is not a remote vulnerability; it requires local code execution privileges to exploit.