8.8
CWE
269
Advisory Published
Updated

CVE-2024-45173

First published: Thu Sep 05 2024(Updated: )

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning sudo privileges, C-MOR is vulnerable to a privilege escalation attack. The Linux user www-data running the C-MOR web interface can execute some OS commands as root via Sudo without having to enter the root password. These commands, for example, include cp, chown, and chmod, which enable an attacker to modify the system's sudoers file in order to execute all commands with root privileges. Thus, it is possible to escalate the limited privileges of the user www-data to root privileges.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
C-MOR Video Surveillance

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2024-45173?

    CVE-2024-45173 has a high severity due to its potential for privilege escalation.

  • How do I fix CVE-2024-45173?

    To fix CVE-2024-45173, ensure that proper privilege management is implemented and restrict unnecessary sudo access for the www-data user.

  • What systems are affected by CVE-2024-45173?

    CVE-2024-45173 impacts the za-internet C-MOR Video Surveillance software version 5.2401.

  • Can CVE-2024-45173 be exploited remotely?

    Yes, CVE-2024-45173 can potentially be exploited remotely due to the vulnerabilities in the web interface.

  • What are the risks of not addressing CVE-2024-45173?

    Failure to address CVE-2024-45173 may allow attackers to escalate privileges and execute commands as root, jeopardizing system security.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203