CVE ID | |
CVSS SCORE | 6.9, AV:L/AC:M/Au:N/C:C/I:C/A:C |
AFFECTED VENDORS |
Joyent |
AFFECTED PRODUCTS |
Smart Data Center |
VULNERABILITY DETAILS |
The specific flaw exists within a Docker remote API for this product. An attacker can create a device node that is the same as /dev/kmem, which can overwrite arbitrary kernel memory. An attacker can leverage this vulnerability to escalate privileges to escape a zone and achieve privileged execution on the Smart Data Center.
|
ADDITIONAL DETAILS | |
DISCLOSURE TIMELINE |
|
CREDIT | Ben Murphy |