Vulnerabilities > CVE-2016-5662 - Multiple Security vulnerability in Accellion Kiteworks Appliance Kw2016.03.00

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
accellion

Summary

Accellion Kiteworks appliances before kw2016.03.00 use setuid-root permissions for /opt/bin/cli, which allows local users to gain privileges via unspecified vectors. <a href="http://cwe.mitre.org/data/definitions/276.html">CWE-276: Incorrect Default Permissions</a>

Vulnerable Configurations

Part Description Count
Application
Accellion
1