Mostrando entradas con la etiqueta CVE-2022-41976. Mostrar todas las entradas
Mostrando entradas con la etiqueta CVE-2022-41976. Mostrar todas las entradas

miƩrcoles, 23 de noviembre de 2022

Scada-LTS - Privilege escalation (CVE-2022-41976)

 



Vulnerability Type: Incorrect Access Control
Affected Product Code Base: Scada-LTS v2.7.1.1 build 2948559113 (or before to v2.7.3)
Affected Component: Affected source code file and API
Attack Type: Remote 
Impact: Privilege escalation, SQL code execution to RCE, arbitrary data alteration, information leakage (e.g. users and password hashes) and service unavailability.
Attack Vectors: To exploit the vulnerability, it is required to be authenticated with a low privilege user.

Description

A remote attacker, authenticated in the application as a low-privileged user, can change role (e.g., to administrator) by updating their user profile.