Vulnerability Description
inSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user from a lower privileged user due to improper integrity checks and directory permissions.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Druva | Insync | 6.8.0 |
Related Weaknesses (CWE)
References
- https://www.tenable.com/security/research/tra-2020-67ExploitThird Party Advisory
- https://www.tenable.com/security/research/tra-2020-67%2Chttps://docs.druva.com/0
- https://www.tenable.com/security/research/tra-2020-67ExploitThird Party Advisory
- https://www.tenable.com/security/research/tra-2020-67%2Chttps://docs.druva.com/0
FAQ
What is CVE-2020-5798?
CVE-2020-5798 is a vulnerability with a CVSS score of 7.8 (HIGH). inSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user from a lower privileged user due to improper integrity checks and directory permis...
How severe is CVE-2020-5798?
CVE-2020-5798 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-5798?
Check the references section above for vendor advisories and patch information. Affected products include: Druva Insync.