CVE-2018-5313

A vulnerability allows local attackers to escalate privilege on Rapid Scada 5.5.0 because of weak C:\SCADA permissions. The specific flaw exists within the access control that is set and modified during the installation of the product. The product sets weak access control restrictions. An attacker can leverage this vulnerability to execute arbitrary code under the context of Administrator, the IUSR account, or SYSTEM.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rapidscada:rapid_scada:5.5.0:*:*:*:*:*:*:*

History

21 Nov 2024, 04:08

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/146668/Rapid-Scada-5.5.0-Insecure-Permissions.html - Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/146668/Rapid-Scada-5.5.0-Insecure-Permissions.html - Third Party Advisory, VDB Entry
References () http://seclists.org/fulldisclosure/2018/Mar/11 - Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2018/Mar/11 - Mailing List, Third Party Advisory

Information

Published : 2018-03-08 20:29

Updated : 2024-11-21 04:08


NVD link : CVE-2018-5313

Mitre link : CVE-2018-5313

CVE.ORG link : CVE-2018-5313


JSON object : View

Products Affected

rapidscada

  • rapid_scada
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource