Impact
The vulnerability is caused by an insecure sudoers configuration that allows the apache account to run /bin/nice without a password, which can be leveraged to invoke arbitrary commands with root privileges. This results in a privilege escalation attack. The weakness is classified as CWE-250, which involves unauthorized use of privileged credentials.
Affected Systems
Telenia Software TVox 26.5.3 and earlier 26.x releases, as well as 24.9.21 and earlier 24.x releases are affected by the insecure sudoers configuration.
Risk and Exploitability
The CVSS v3.1 score is 8.5, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local: an attacker who can run commands as the apache user can exploit the NOPASSWD rule to execute arbitrary commands as root, leading to full system compromise. Because any user who has access to the web server can potentially trigger the exploit, the risk of exploitation is significant in environments where the apache account is not strictly isolated.
OpenCVE Enrichment