Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
HPE Warns Sudo Bug Gives Attackers Root Privileges to Aruba Platform
#1
Information 
Quote:Hewlett Packard Enterprise (HPE) is warning a vulnerability in Sudo, an open-source program used within its Aruba AirWave management platform, could allow any unprivileged and unauthenticated local user to gain root privileges on a vulnerable host.
 
Rated high in severity, HPE warns the Sudo flaw could be part of a “chained attack” where an “attacker has achieved a foothold with lower privileges via another vulnerability and then uses this to escalate privileges,” according to a recent HPE security bulletin.
 
The Aruba AirWave management platform is HPE’s real-time monitoring and security alert system for wired and wireless infrastructures. The Sudo bug (CVE-2021-3156) was reported in January by Qualys researchers and is believed to impact millions of endpoint devices and systems.

Sudo is a program used by other platforms that “allows a system administrator to delegate authority to give certain users (or groups of users) the ability to run some (or all) commands as root or another user,” according to the Sudo license.

Read more: HPE Warns Sudo Bug Gives Attackers Root Privileges to Aruba Platform
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
GFYI [Official] AIDA64 Extreme Mother's...
"What feature/s...damien76 — 07:36
GFYI [Official] EaseUS Todo Backup Home...
"Share feedback...damien76 — 07:30
Manjaro Linux 24.0 Build 240513
Manjaro Linux 24.0...harlan4096 — 06:01
Mozilla Firefox Browser 126.0
Mozilla Firefox Br...harlan4096 — 06:01
Adobe Acrobat Reader DC 2024.002.20759
Adobe Acrobat Read...harlan4096 — 06:00

[-]
Birthdays
Today's Birthdays
avatar (43)tiojusop
avatar (40)Damiennug
avatar (38)acoraxe
Upcoming Birthdays
avatar (26)akiratoriyama
avatar (46)Jerrycix
avatar (38)awedoli
avatar (80)WinRARHowTo
avatar (37)axuben
avatar (38)ihijudu
avatar (47)contjrat
avatar (42)knigiJow
avatar (44)1stOnecal
avatar (48)Mirzojap
avatar (34)idilysaju
avatar (38)GregoryRog
avatar (43)mediumog
avatar (38)odukoromu
avatar (44)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>