CVE-2017-8126
published 2017-11-22CVE-2017-8126: The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker…
PriorityP347critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.05%
60.2th percentile
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| condor_project | condor | >= 0 < 8.0.5~dfsg.1-1ubuntu1+esm1 | 8.0.5~dfsg.1-1ubuntu1+esm1 |
| condor_project | condor | >= 0 < 8.4.2~dfsg.1-1ubuntu0.1~esm1 | 8.4.2~dfsg.1-1ubuntu0.1~esm1 |
| huawei | uma | — | — |
| huawei_technologies_co_ltd | uma | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4q96-97v6-xq9v: The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters
ghsa_unreviewed·2022-05-13
CVE-2017-8126 [CRITICAL] CWE-20 GHSA-4q96-97v6-xq9v: The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
OSV
condor vulnerabilities
osv·2021-03-15·CVSS 8.8
CVE-2014-8126 condor vulnerabilities
condor vulnerabilities
It was discovered that HTCondor incorrectly invoked the mailx utility. An
attacker could use this vulnerability to execute arbitrary commands. This
issue only affected Ubuntu 14.04 ESM. (CVE-2014-8126)
It was discovered that HTCondor mishandled certain crafted input. An
attacker could use this vulnerability to cause HTCondor to crash.
(CVE-2017-16816)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-11-22
Published