Henry Reed

2 exploits Active since May 2022
CVE-2022-0997 NOMISEC LOW WRITEUP
Fidelissecurity Deception < 9.4.5 - Incorrect Default Permissions
Improper file permissions in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected script files, which could result in arbitrary commands being run as root upon subsequent logon by a root user. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.
1 stars
CVSS 3.9
CVE-2022-0486 NOMISEC MEDIUM WORKING POC
Fidelis Network & Deception <9.4.5 - Privilege Escalation
Improper file permissions in the CommandPost, Collector, Sensor, and Sandbox components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected files and enable escalation of privileges equivalent to the root user. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.
CVSS 4.4