Vulnerability in Fujitsu PlugFree Network

An unquoted service path allows a possible extension of rights at the system level.

Twitter
LinkedIn
Facebook

Vulnerability type

Privilege Escalation

Pentester

Florian Hansemann

Publication

Software version

PlugFree Network Version <= 7.3.0.3

Timeline

– 28.10.2021 Manufacturer informs

– 22.11.2021 Manufacturer contacted again

– 10.12.2021 Public tweet to the manufacturer

– 19.12.2021 Manufacturer contacted again

– 14.04.2022 Release CVE