CVE-2022-29549: High severity qualys cloud agent vulnerability
An issue was discovered in Qualys Cloud Agent 4.8.0-49. It executes programs at various full pathnames without first making ownership and permission checks (e.g., to help ensure that a program was installed by root) and without integrity checks (e.g., a checksum comparison against known legitimate programs). Also, the vendor recommendation is to install this agent software with root privileges. Thus, privilege escalation is possible on systems where any of these pathnames is controlled by a non-root user. An example is /opt/firebird/bin/isql, where the /opt/firebird directory is often owned by the firebird user.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-29549.
What is the severity of CVE-2022-29549?
The severity of CVE-2022-29549 is high with a severity score of 7.3.
What software is affected by CVE-2022-29549?
Qualys Cloud Agent for Linux versions up to 2.5.548.2 is affected by CVE-2022-29549.
What is the description of CVE-2022-29549?
CVE-2022-29549 is an issue in Qualys Cloud Agent 4.8.0-49 where it executes programs without proper ownership and permission checks and integrity checks, leading to potential arbitrary code execution.
Are there any references for CVE-2022-29549?
Yes, there are references available for CVE-2022-29549. You can find them at the following links: [Reference 1](http://packetstormsecurity.com/files/168367/Qualys-Cloud-Agent-Arbitrary-Code-Execution.html), [Reference 2](http://seclists.org/fulldisclosure/2022/Sep/10), [Reference 3](http://software.firstworks.com/p/getting-started-with-firebird.html).