Privilege Escalation Vulnerability in Infoblox NIOS by Infoblox
CVE-2018-10239
6.7MEDIUM
What is CVE-2018-10239?
A vulnerability exists in the 'support access' feature of Infoblox NIOS versions 6.8 through 8.4.1, allowing a locally authenticated administrator to gain elevated privileges temporarily. This arises from a flaw in the support access password generation method, enabling a potentially malicious administrator, who knows both the current session's support access code and the underlying password generation algorithm, to exploit this flaw if the feature is enabled. By default, 'support access' is disabled, and it automatically expires after 24 hours when enabled.
