7.2
CVSSv2

CVE-2017-7968

Published: 19/05/2017 Updated: 09/10/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An Incorrect Default Permissions issue exists in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. Upon installation, Wonderware InduSoft Web Studio creates a new directory and two files, which are placed in the system's path and can be manipulated by non-administrators. This could allow an authenticated user to escalate his or her privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric wonderware indusoft web studio

Exploits

Schneider Electric Wonderware InduSoft Web Studio versions 80 Patch 3 and below suffer from having incorrect default permissions ...