CVE-2022-29549 is a privilege escalation vulnerability affecting Qualys Cloud Agent 4.8.0-49 for Linux. The agent executes programs from various full pathnames without proper ownership, permission, or integrity checks, allowing a non-root user to potentially control these paths and elevate privileges. Rated as High severity with a CVSS score of 7.3, this vulnerability requires local access and user interaction (UI:R) to achieve high impact on confidentiality, integrity, and availability. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.5.548.2CPE matchmatch criteria | cpe:2.3:a:qualys:cloud_agent_for_linux:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Possible local privilege escalation for Qualys Cloud Agent for Linux with Manifest versions prior to 2.5.548.2
Aug 15, 2022Possible local privilege escalation for Qualys Cloud Agent for Linux with Manifest versions prior to 2.5.548.2
Aug 15, 2022Possible local privilege escalation for Qualys Cloud Agent for Linux with Manifest versions prior to 2.5.548.2
Aug 15, 2022Possible local privilege escalation for Qualys Cloud Agent for Linux with Manifest versions prior to 2.5.548.2
Aug 15, 2022Possible local privilege escalation for Qualys Cloud Agent for Linux with Manifest versions prior to 2.5.548.2
Aug 15, 2022Possible local privilege escalation for Qualys Cloud Agent for Linux with Manifest versions prior to 2.5.548.2
Aug 15, 2022