There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of sensible files (such as the shadow file) or privilege escalation by manually adding a new user with sudo privileges on the machine.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/aliasrobotics/RVD/issues/2562 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: Alias
Published: 2020-06-24T04:55:17.409872Z
Updated: 2024-09-17T02:27:32.380Z
Reserved: 2020-03-10T00:00:00
Link: CVE-2020-10277
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-06-24T05:15:13.347
Modified: 2024-11-21T04:55:07.380
Link: CVE-2020-10277
Redhat
No data.