Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash scripts. If these scripts are writable by web-facing users or accessible via command injection, attackers can replace them with malicious payloads. Execution with sudo grants full root access, resulting in remote privilege escalation and potential system compromise.
CVSS
No CVSS.
References
Configurations
No configuration.
History
16 Sep 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-16 20:15
Updated : 2025-09-17 14:18
NVD link : CVE-2025-34187
Mitre link : CVE-2025-34187
CVE.ORG link : CVE-2025-34187
JSON object : View
Products Affected
No product.