Total
3
Critical
0
High
0
Medium
0
CISA KEV
0
The dhcp.client program for QNX 4.25 vmware is setuid, possibly by default, which allows local users to modify the NIC configuration and conduct other attacks.
QNX 2.4 allows a local user to read arbitrary files by directly accessing the mount point for the FAT disk partition, e.g. /fs-dos.
The crypt function in QNX uses weak encryption, which allows local users to decrypt passwords.