Security Vulnerability Notice - CVE-2017-6516

A local privileged root escalation vulnerability has been found and fixed in MagniComp's SysInfo product. The vulnerability allows local attackers to run local commands as root including the ability to run get a shell prompt as root.

This vulnerability was first reported by MWR Labs Security Advisory and is detailed here and here.

Details

  • Notice Date: Aug 23, 2016
  • Last Update: Mar 14, 2017
  • Affected Product Versions: All versions of SysInfo prior to 10-H64
  • Affected Product Platforms: All Linux and UNIX platforms
  • Fixed In: Version 10-H64 and later