The sudo rules configured for a local service account were excessively permissive, potentially allowing administrative access if a malicious actor could execute arbitrary commands as that account.
It is important to note that no such vector has been identified in this instance.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to v24.6.0 or later.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54661 | A privilege escalation vulnerability may enable a service account to elevate its privileges. The sudo rules configured for a local service account were excessively permissive, potentially allowing administrative access if a malicious actor could execute arbitrary commands as that account. It is important to note that no such vector has been identified in this instance. |
| Link | Providers |
|---|---|
| https://security.nozominetworks.com/NN-2025:2-01 |
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 10 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Jun 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A privilege escalation vulnerability may enable a service account to elevate its privileges. The sudo rules configured for a local service account were excessively permissive, potentially allowing administrative access if a malicious actor could execute arbitrary commands as that account. It is important to note that no such vector has been identified in this instance. | |
| Title | Privilege escalation in Guardian/CMC before 24.6.0 | |
| Weaknesses | CWE-250 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Nozomi
Published:
Updated: 2025-06-10T14:28:19.863Z
Reserved: 2024-12-31T11:12:59.363Z
Link: CVE-2024-13090
Updated: 2025-06-10T14:28:09.811Z
Status : Deferred
Published: 2025-06-10T11:15:52.477
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-13090
No data.
OpenCVE Enrichment
No data.
EUVD