Vulnerabilities > CVE-2022-2104 - Unspecified vulnerability in Secheron Sepcos Control and Protection Relay Firmware

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
secheron

Summary

The www-data (Apache web server) account is configured to run sudo with no password for many commands (including /bin/sh and /bin/bash).