A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 6
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Trueconf Trueconf_Server
cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:windows:*:*
|
— |
5.3.9.10013
|
|
Trueconf Trueconf_Server
cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:linux_kernel:*:*
|
— |
5.3.9.10015
|
|
Trueconf Trueconf_Server
cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:windows:*:*
|
5.4.0.12689
|
5.4.9.10072
|
|
Trueconf Trueconf_Server
cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:linux_kernel:*:*
|
5.4.0.12700
|
5.4.9.10019
|
|
Trueconf Trueconf_Server
cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:windows:*:*
|
5.5.0.13826
|
5.5.5.10010
|
|
Trueconf Trueconf_Server
cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:linux_kernel:*:*
|
5.5.0.13828
|
5.5.5.10009
|