Impact
A local user with command‑line access can elevate privileges and inject parameters by abusing a misconfigured sudoers entry that grants a command. The vulnerability stems from improper privilege management (CWE‑266) and allows the local attacker to run privileged commands with manipulated arguments.
Affected Systems
The issue affects Algosec Horizon Security Analyzer versions A33.10, A33.20, and A33.30 on Linux (64‑bit). A33.10 is vulnerable up to build 300, A33.20 up to build 170, and A33.30 up to build 110.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; an attacker must have a local account with command‑line access and rely on the misconfigured sudoers file. Once exploited, the attacker can achieve full root privileges and potentially inject malicious parameters into privileged commands.
OpenCVE Enrichment