First published: Tue May 02 2023(Updated: )
In Nokia One-NDS (aka Network Directory Server) through 20.9, some Sudo permissions can be exploited by some users to escalate to root privileges and execute arbitrary commands.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nokia One-NDS | <=20.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30759 is a vulnerability in Nokia One-NDS (aka Network Directory Server) versions up to and including 20.9 that allows some users to escalate their privileges to root and execute arbitrary commands.
CVE-2022-30759 has a severity rating of 8.8 (high).
To exploit CVE-2022-30759, some users can abuse certain Sudo permissions to gain root privileges and run arbitrary commands.
CVE-2022-30759 affects Nokia One-NDS (aka Network Directory Server) versions up to and including 20.9.
Yes, you can find more information about CVE-2022-30759 at the following links: [Packet Storm Security](https://packetstormsecurity.com/files/171971/Nokia-OneNDS-20.9-Insecure-Permissions-Privilege-Escalation.html) and [Nokia One-NDS Product Page](https://www.nokia.com/networks/products/one-nds/).