{"id":21908,"date":"2021-07-23T16:56:11","date_gmt":"2021-07-23T15:56:11","guid":{"rendered":"https:\/\/www.n-able.com\/?p=21908"},"modified":"2021-07-23T16:56:11","modified_gmt":"2021-07-23T15:56:11","slug":"linux-vulnerability-cve-2021-33909-sequoia-and-n-central","status":"publish","type":"post","link":"https:\/\/www.n-able.com\/it\/blog\/linux-vulnerability-cve-2021-33909-sequoia-and-n-central","title":{"rendered":"Linux Vulnerability CVE-2021-33909 (Sequoia) and N&#8209;central"},"content":{"rendered":"<p class=\"p2\"><span class=\"s1\">As more information about the recently disclosed, local privilege escalation Linux vulnerability, Sequoia (<a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-33909\" target=\"_blank\" rel=\"noopener\"><span class=\"s2\">CVE-2021-33909<\/span><\/a>), comes to light, we wanted to keep our partners in the loop. This is a vulnerability all MSPs who support or use Linux systems should be aware of. Based on our understanding of it, it\u2019s unlikely to be a risk to the N&#8209;able<sup>\u2122<\/sup> N&#8209;central<sup>\u00ae<\/sup> platform. To exploit the vulnerability an attacker needs to have local shell access. While a customer running N&#8209;central is potentially at risk, this risk is mitigated by the fact that N&#8209;central runs on a hardened virtual appliance with local OS access disabled. <\/span><\/p>\n<p class=\"p2\"><span class=\"s1\">We are diligently working on a patch to disable this Linux filesystem vulnerability and will notify customers as soon as it is available for download. To stay up to date with feature updates, hotfixes, and any new information concerning this issue, please make sure you are subscribed to our <a href=\"https:\/\/status.n-able.com\/release-notes\/\" target=\"_blank\" rel=\"noopener\"><span class=\"s2\">Release Notes<\/span><\/a> as well as the <a href=\"https:\/\/www.n-able.com\/blog\/hardening-n-able-rmm\" target=\"_blank\" rel=\"noopener\"><span class=\"s2\">N&#8209;able Blog<\/span><\/a> (see the subscribe box at the bottom of the blog).<\/span><\/p>\n<p class=\"p2\"><span class=\"s1\">For partners running Linux systems that allow system access, we strongly advise you to immediately apply the relevant Linux kernel patch. For additional information, refer to the <a href=\"https:\/\/blog.qualys.com\/vulnerabilities-threat-research\/2021\/07\/20\/sequoia-a-local-privilege-escalation-vulnerability-in-linuxs-filesystem-layer-cve-2021-33909\" target=\"_blank\" rel=\"noopener\"><span class=\"s2\">original announcement from Qualys<\/span><\/a> or the <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-33909\" target=\"_blank\" rel=\"noopener\"><span class=\"s2\">NIST CVE details\u00a0<\/span><\/a>.<\/span><\/p>\n<p class=\"p2\"><span class=\"s1\">If you have any questions, don\u2019t hesitate to reach out to me out my contact information below.<\/span><\/p>\n<p class=\"p5\"><span class=\"s1\"><i>Lewis Pope is the Head Security Nerd at N&#8209;able. You can follow him on<\/i><\/span><\/p>\n<p class=\"p6\"><span class=\"s3\"><i>Twitter:\u00a0<\/i><a href=\"https:\/\/twitter.com\/cybersec_nerd\" target=\"_blank\" rel=\"noopener\"><span class=\"s4\"><i>@cybersec_nerd<\/i><\/span><\/a><\/span><\/p>\n<p class=\"p6\"><span class=\"s3\"><i>Linkedin:\u00a0<\/i><a href=\"https:\/\/www.linkedin.com\/in\/thesecuritypope\"><span class=\"s4\"><i>thesecuritypope<\/i><\/span><\/a><\/span><\/p>\n<p class=\"p6\"><span class=\"s3\"><i>Twitch:\u00a0<\/i><a href=\"https:\/\/www.twitch.tv\/cybersec_nerd\" target=\"_blank\" rel=\"noopener\"><span class=\"s4\"><i>cybersec_nerd<\/i><\/span><\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As more information comes to light about the recently disclosed, local privilege escalation Linux vulnerability, Sequoia, Lewis Pope keeps our partners in the loop.<\/p>\n","protected":false},"author":62,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"class_list":["post-21908","post","type-post","status-publish","format-standard","hentry","topic-head-nerds","topic-security"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.2 (Yoast SEO v27.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Linux Vulnerability CVE-2021-33909 (Sequoia) and N-central - N-able<\/title>\n<meta name=\"description\" content=\"As more information comes to light about the recently disclosed Linux vulnerability, Sequoia, we keep our partners in the loop.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.n-able.com\/it\/blog\/linux-vulnerability-cve-2021-33909-sequoia-and-n-central\" \/>\n<meta property=\"og:locale\" content=\"it_IT\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Linux Vulnerability CVE-2021-33909 (Sequoia) and N-central - N-able\" \/>\n<meta property=\"og:description\" content=\"As more information comes to light about the recently disclosed Linux vulnerability, Sequoia, we keep our partners in the loop.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.n-able.com\/it\/blog\/linux-vulnerability-cve-2021-33909-sequoia-and-n-central\" \/>\n<meta property=\"og:site_name\" content=\"N-able\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/NableMSP\" \/>\n<meta property=\"article:published_time\" content=\"2021-07-23T15:56:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.n-able.com\/wp-content\/uploads\/2021\/04\/blog-Lewis-Pope.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"720\" \/>\n\t<meta property=\"og:image:height\" content=\"356\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Lewis Pope\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.n-able.com\/wp-content\/uploads\/2021\/04\/blog-Lewis-Pope.jpg\" \/>\n<meta name=\"twitter:creator\" content=\"@Nable\" \/>\n<meta name=\"twitter:site\" content=\"@Nable\" \/>\n<meta name=\"twitter:label1\" content=\"Scritto da\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lewis Pope\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tempo di lettura stimato\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minuti\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.n-able.com\/it\/blog\/linux-vulnerability-cve-2021-33909-sequoia-and-n-central#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.n-able.com\/it\/blog\/linux-vulnerability-cve-2021-33909-sequoia-and-n-central\"},\"author\":{\"name\":\"Lewis Pope\",\"@id\":\"https:\/\/www.n-able.com\/it\/#\/schema\/person\/32c214c92846fdd7b16459b9236c12ae\"},\"headline\":\"Linux Vulnerability CVE-2021-33909 (Sequoia) and N&#8209;central\",\"datePublished\":\"2021-07-23T16:56:11+01:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.n-able.com\/it\/blog\/linux-vulnerability-cve-2021-33909-sequoia-and-n-central\"},\"wordCount\":252,\"publisher\":{\"@id\":\"https:\/\/www.n-able.com\/it\/#organization\"},\"articleSection\":[\"Head Nerds\",\"Security\"],\"inLanguage\":\"it-IT\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.n-able.com\/it\/blog\/linux-vulnerability-cve-2021-33909-sequoia-and-n-central\",\"url\":\"https:\/\/www.n-able.com\/it\/blog\/linux-vulnerability-cve-2021-33909-sequoia-and-n-central\",\"name\":\"Linux Vulnerability CVE-2021-33909 (Sequoia) and N-central - N-able\",\"isPartOf\":{\"@id\":\"https:\/\/www.n-able.com\/it\/#website\"},\"datePublished\":\"2021-07-23T16:56:11+01:00\",\"description\":\"As more information comes to light about the recently disclosed Linux vulnerability, Sequoia, we keep our partners in the loop.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.n-able.com\/it\/blog\/linux-vulnerability-cve-2021-33909-sequoia-and-n-central#breadcrumb\"},\"inLanguage\":\"it-IT\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.n-able.com\/it\/blog\/linux-vulnerability-cve-2021-33909-sequoia-and-n-central\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.n-able.com\/it\/blog\/linux-vulnerability-cve-2021-33909-sequoia-and-n-central#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Head Nerds\",\"item\":\"https:\/\/www.n-able.com\/it\/blog\/category\/head-nerds-it\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Linux Vulnerability CVE-2021-33909 (Sequoia) and N&#8209;central\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.n-able.com\/it\/#website\",\"url\":\"https:\/\/www.n-able.com\/it\/\",\"name\":\"N-able\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.n-able.com\/it\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.n-able.com\/it\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"it-IT\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.n-able.com\/it\/#organization\",\"name\":\"N-able\",\"url\":\"https:\/\/www.n-able.com\/it\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"it-IT\",\"@id\":\"https:\/\/www.n-able.com\/it\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.n-able.com\/wp-content\/uploads\/2021\/02\/logo-n-able-vertical-dark.svg\",\"contentUrl\":\"https:\/\/www.n-able.com\/wp-content\/uploads\/2021\/02\/logo-n-able-vertical-dark.svg\",\"width\":\"1024\",\"height\":\"1024\",\"caption\":\"N-able\"},\"image\":{\"@id\":\"https:\/\/www.n-able.com\/it\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/NableMSP\",\"https:\/\/x.com\/Nable\",\"https:\/\/www.linkedin.com\/company\/n-able\",\"https:\/\/www.youtube.com\/channel\/UClnp77HHg4aME-S-3fWQhFw\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.n-able.com\/it\/#\/schema\/person\/32c214c92846fdd7b16459b9236c12ae\",\"name\":\"Lewis Pope\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"it-IT\",\"@id\":\"https:\/\/secure.gravatar.com\/avatar\/f61d746b384dec3b7d702cd5a5e62b2d6a9722dd83df5ae50505361c3a3eadb1?s=96&d=mm&r=g\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/f61d746b384dec3b7d702cd5a5e62b2d6a9722dd83df5ae50505361c3a3eadb1?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/f61d746b384dec3b7d702cd5a5e62b2d6a9722dd83df5ae50505361c3a3eadb1?s=96&d=mm&r=g\",\"caption\":\"Lewis Pope\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Linux Vulnerability CVE-2021-33909 (Sequoia) and N-central - N-able","description":"As more information comes to light about the recently disclosed Linux vulnerability, Sequoia, we keep our partners in the loop.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.n-able.com\/it\/blog\/linux-vulnerability-cve-2021-33909-sequoia-and-n-central","og_locale":"it_IT","og_type":"article","og_title":"Linux Vulnerability CVE-2021-33909 (Sequoia) and N-central - N-able","og_description":"As more information comes to light about the recently disclosed Linux vulnerability, Sequoia, we keep our partners in the loop.","og_url":"https:\/\/www.n-able.com\/it\/blog\/linux-vulnerability-cve-2021-33909-sequoia-and-n-central","og_site_name":"N-able","article_publisher":"https:\/\/www.facebook.com\/NableMSP","article_published_time":"2021-07-23T15:56:11+00:00","og_image":[{"width":720,"height":356,"url":"https:\/\/www.n-able.com\/wp-content\/uploads\/2021\/04\/blog-Lewis-Pope.jpg","type":"image\/jpeg"}],"author":"Lewis Pope","twitter_card":"summary_large_image","twitter_image":"https:\/\/www.n-able.com\/wp-content\/uploads\/2021\/04\/blog-Lewis-Pope.jpg","twitter_creator":"@Nable","twitter_site":"@Nable","twitter_misc":{"Scritto da":"Lewis Pope","Tempo di lettura stimato":"2 minuti"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.n-able.com\/it\/blog\/linux-vulnerability-cve-2021-33909-sequoia-and-n-central#article","isPartOf":{"@id":"https:\/\/www.n-able.com\/it\/blog\/linux-vulnerability-cve-2021-33909-sequoia-and-n-central"},"author":{"name":"Lewis Pope","@id":"https:\/\/www.n-able.com\/it\/#\/schema\/person\/32c214c92846fdd7b16459b9236c12ae"},"headline":"Linux Vulnerability CVE-2021-33909 (Sequoia) and N&#8209;central","datePublished":"2021-07-23T16:56:11+01:00","mainEntityOfPage":{"@id":"https:\/\/www.n-able.com\/it\/blog\/linux-vulnerability-cve-2021-33909-sequoia-and-n-central"},"wordCount":252,"publisher":{"@id":"https:\/\/www.n-able.com\/it\/#organization"},"articleSection":["Head Nerds","Security"],"inLanguage":"it-IT"},{"@type":"WebPage","@id":"https:\/\/www.n-able.com\/it\/blog\/linux-vulnerability-cve-2021-33909-sequoia-and-n-central","url":"https:\/\/www.n-able.com\/it\/blog\/linux-vulnerability-cve-2021-33909-sequoia-and-n-central","name":"Linux Vulnerability CVE-2021-33909 (Sequoia) and N-central - N-able","isPartOf":{"@id":"https:\/\/www.n-able.com\/it\/#website"},"datePublished":"2021-07-23T16:56:11+01:00","description":"As more information comes to light about the recently disclosed Linux vulnerability, Sequoia, we keep our partners in the loop.","breadcrumb":{"@id":"https:\/\/www.n-able.com\/it\/blog\/linux-vulnerability-cve-2021-33909-sequoia-and-n-central#breadcrumb"},"inLanguage":"it-IT","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.n-able.com\/it\/blog\/linux-vulnerability-cve-2021-33909-sequoia-and-n-central"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.n-able.com\/it\/blog\/linux-vulnerability-cve-2021-33909-sequoia-and-n-central#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Head Nerds","item":"https:\/\/www.n-able.com\/it\/blog\/category\/head-nerds-it"},{"@type":"ListItem","position":2,"name":"Linux Vulnerability CVE-2021-33909 (Sequoia) and N&#8209;central"}]},{"@type":"WebSite","@id":"https:\/\/www.n-able.com\/it\/#website","url":"https:\/\/www.n-able.com\/it\/","name":"N-able","description":"","publisher":{"@id":"https:\/\/www.n-able.com\/it\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.n-able.com\/it\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"it-IT"},{"@type":"Organization","@id":"https:\/\/www.n-able.com\/it\/#organization","name":"N-able","url":"https:\/\/www.n-able.com\/it\/","logo":{"@type":"ImageObject","inLanguage":"it-IT","@id":"https:\/\/www.n-able.com\/it\/#\/schema\/logo\/image\/","url":"https:\/\/www.n-able.com\/wp-content\/uploads\/2021\/02\/logo-n-able-vertical-dark.svg","contentUrl":"https:\/\/www.n-able.com\/wp-content\/uploads\/2021\/02\/logo-n-able-vertical-dark.svg","width":"1024","height":"1024","caption":"N-able"},"image":{"@id":"https:\/\/www.n-able.com\/it\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/NableMSP","https:\/\/x.com\/Nable","https:\/\/www.linkedin.com\/company\/n-able","https:\/\/www.youtube.com\/channel\/UClnp77HHg4aME-S-3fWQhFw"]},{"@type":"Person","@id":"https:\/\/www.n-able.com\/it\/#\/schema\/person\/32c214c92846fdd7b16459b9236c12ae","name":"Lewis Pope","image":{"@type":"ImageObject","inLanguage":"it-IT","@id":"https:\/\/secure.gravatar.com\/avatar\/f61d746b384dec3b7d702cd5a5e62b2d6a9722dd83df5ae50505361c3a3eadb1?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f61d746b384dec3b7d702cd5a5e62b2d6a9722dd83df5ae50505361c3a3eadb1?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f61d746b384dec3b7d702cd5a5e62b2d6a9722dd83df5ae50505361c3a3eadb1?s=96&d=mm&r=g","caption":"Lewis Pope"}}]}},"_links":{"self":[{"href":"https:\/\/www.n-able.com\/it\/wp-json\/wp\/v2\/posts\/21908","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.n-able.com\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.n-able.com\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.n-able.com\/it\/wp-json\/wp\/v2\/users\/62"}],"replies":[{"embeddable":true,"href":"https:\/\/www.n-able.com\/it\/wp-json\/wp\/v2\/comments?post=21908"}],"version-history":[{"count":0,"href":"https:\/\/www.n-able.com\/it\/wp-json\/wp\/v2\/posts\/21908\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.n-able.com\/it\/wp-json\/wp\/v2\/media?parent=21908"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}