Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, Parameter Injection.
A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file.
This issue affects Firewall Analyzer: A33.0, A33.10.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file. This issue affects Firewall Analyzer: A33.0, A33.10. | |
| Title | Privilege Escalation via Misconfigured Sudoers Entry for Local Users in AlgoSec Firewall Analyzer | |
| First Time appeared |
Algosec
Algosec firewall Analyzer |
|
| Weaknesses | CWE-269 | |
| CPEs | cpe:2.3:a:algosec:firewall_analyzer:a33.0:*:64_bit:*:*:*:*:* cpe:2.3:a:algosec:firewall_analyzer:a33.0:*:linux:*:*:*:*:* cpe:2.3:a:algosec:firewall_analyzer:a33.10:*:64_bit:*:*:*:*:* cpe:2.3:a:algosec:firewall_analyzer:a33.10:*:linux:*:*:*:*:* |
|
| Vendors & Products |
Algosec
Algosec firewall Analyzer |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: AlgoSec
Published: 2025-12-09T13:41:53.393Z
Updated: 2025-12-09T14:26:01.398Z
Reserved: 2025-10-28T09:05:51.106Z
Link: CVE-2025-12381
Updated: 2025-12-09T14:25:58.539Z
Status : Awaiting Analysis
Published: 2025-12-09T16:17:33.910
Modified: 2025-12-09T18:37:13.640
Link: CVE-2025-12381
No data.