Description
Infotecs ViPNet Client and Coordinator before 4.3.2-42442 allow local users to gain privileges by placing a Trojan horse ViPNet update file in the update folder. The attack succeeds because of incorrect folder permissions in conjunction with a lack of integrity and authenticity checks.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-18537 | Infotecs ViPNet Client and Coordinator before 4.3.2-42442 allow local users to gain privileges by placing a Trojan horse ViPNet update file in the update folder. The attack succeeds because of incorrect folder permissions in conjunction with a lack of integrity and authenticity checks. |
References
| Link | Providers |
|---|---|
| https://github.com/Houl777/CVE-2017-9606 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T17:11:02.326Z
Reserved: 2017-06-13T00:00:00.000Z
Link: CVE-2017-9606
No data.
Status : Modified
Published: 2017-06-15T03:29:00.167
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-9606
No data.
OpenCVE Enrichment
No data.
EUVD