7.8
CVSSv3

CVE-2018-5313

Published: 08/03/2018 Updated: 24/08/2020
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A vulnerability allows local malicious users to escalate privilege on Rapid Scada 5.5.0 because of weak C:\SCADA permissions. The specific flaw exists within the access control that is set and modified during the installation of the product. The product sets weak access control restrictions. An attacker can leverage this vulnerability to execute arbitrary code under the context of Administrator, the IUSR account, or SYSTEM.

Vulnerable Product Search on Vulmon Subscribe to Product

rapidscada rapid scada 5.5.0

Exploits

A vulnerability allows local attackers to escalate privilege on TotalAV versions 417 through 4619 because of weak "C:\Program Files\TotalAV" permissions The specific flaw exists within the access control that is set and modified during the installation of the product The product sets weak access control restrictions An attacker can leverage ...
Rapid Scada version 550 suffers from an insecure permission vulnerability ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Total AV 417 ~ 4 619 - Insecure Permissions <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: filipe &l ...