CVE-2017-7968
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. Upon installation, Wonderware InduSoft Web Studio creates a new directory and two files, which are placed in the system's path and can be manipulated by non-administrators. This could allow an authenticated user to escalate his or her privileges.
Un problema de permisos predeterminado incorrecto se descubrió en Schneider Electric Wonderware InduSoft Web Studio v8.0 revisión 3 y versiones anteriores. Después de la instalación, Wonderware InduSoft Web Studio crea un nuevo directorio y dos archivos, que se colocan en la ruta del sistema y pueden ser manipulados por no administradores. Esto podría permitir a un usuario autenticado escalar sus privilegios.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-04-19 CVE Reserved
- 2017-05-19 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-276: Incorrect Default Permissions
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/98544 | Third Party Advisory | |
https://ics-cert.us-cert.gov/advisories/ICSA-17-138-02 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2017-090-02 | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Schneider-electric Search vendor "Schneider-electric" | Wonderware Indusoft Web Studio Search vendor "Schneider-electric" for product "Wonderware Indusoft Web Studio" | <= 8.0 Search vendor "Schneider-electric" for product "Wonderware Indusoft Web Studio" and version " <= 8.0" | - |
Affected
|