// For flags

CVE-2023-29066

Incorrect User Management

Severity Score

3.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The FACSChorus software does not properly assign data access privileges for operating system user accounts. A non-administrative OS account can modify information stored in the local application data folders.

El software FACSChorus no asigna correctamente privilegios de acceso a datos para las cuentas de usuario del sistema operativo. Una cuenta de sistema operativo no administrativa puede modificar la informaciĆ³n almacenada en las carpetas de datos de la aplicaciĆ³n local.

*Credits: N/A
CVSS Scores
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-03-30 CVE Reserved
  • 2023-11-28 CVE Published
  • 2023-12-06 EPSS Updated
  • 2024-08-02 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-266: Incorrect Privilege Assignment
  • CWE-269: Improper Privilege Management
CAPEC
  • CAPEC-639: Probe System Files
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Bd
Search vendor "Bd"
Facschorus
Search vendor "Bd" for product "Facschorus"
5.0
Search vendor "Bd" for product "Facschorus" and version "5.0"
-
Affected
in Hp
Search vendor "Hp"
Hp Z2 Tower G9
Search vendor "Hp" for product "Hp Z2 Tower G9"
--
Safe
Bd
Search vendor "Bd"
Facschorus
Search vendor "Bd" for product "Facschorus"
5.1
Search vendor "Bd" for product "Facschorus" and version "5.1"
-
Affected
in Hp
Search vendor "Hp"
Hp Z2 Tower G9
Search vendor "Hp" for product "Hp Z2 Tower G9"
--
Safe
Bd
Search vendor "Bd"
Facschorus
Search vendor "Bd" for product "Facschorus"
3.0
Search vendor "Bd" for product "Facschorus" and version "3.0"
-
Affected
in Hp
Search vendor "Hp"
Hp Z2 Tower G5
Search vendor "Hp" for product "Hp Z2 Tower G5"
--
Safe
Bd
Search vendor "Bd"
Facschorus
Search vendor "Bd" for product "Facschorus"
3.1
Search vendor "Bd" for product "Facschorus" and version "3.1"
-
Affected
in Hp
Search vendor "Hp"
Hp Z2 Tower G5
Search vendor "Hp" for product "Hp Z2 Tower G5"
--
Safe