7.8
CVSSv3

CVE-2018-5313

Published: 08/03/2018 Updated: 24/08/2020
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A vulnerability allows local malicious users to escalate privilege on Rapid Scada 5.5.0 because of weak C:\SCADA permissions. The specific flaw exists within the access control that is set and modified during the installation of the product. The product sets weak access control restrictions. An attacker can leverage this vulnerability to execute arbitrary code under the context of Administrator, the IUSR account, or SYSTEM.

Vulnerable Product Search on Vulmon Subscribe to Product

rapidscada rapid scada 5.5.0

Exploits

Rapid Scada version 550 suffers from an insecure permission vulnerability ...
A vulnerability allows local attackers to escalate privilege on TotalAV versions 417 through 4619 because of weak "C:\Program Files\TotalAV" permissions The specific flaw exists within the access control that is set and modified during the installation of the product The product sets weak access control restrictions An attacker can leverage ...

Mailing Lists

=====[ Tempest Security Intelligence - ADV-23/2018 ]=== Total AV 417 ~ 4 619 - Insecure Permissions ------------------------------------------------------- Author: - Filipe Xavier Oliveira: < filipexavier () tempestcombr <tempestcombr/> =====[ Table of Contents ]===================================================== ...