Lucene search

K
cveZdiCVE-2018-1168
HistoryFeb 21, 2018 - 2:29 p.m.

CVE-2018-1168

2018-02-2114:29:00
CWE-732
CWE-284
zdi
web.nvd.nist.gov
26
vulnerability
abb
microscada
9.3
privilege escalation
access controls
zdi-can-5097
cve-2018-1168

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

23.4%

This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB MicroSCADA 9.3 with FP 1-2-3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of the access controls for the installed product files. The installation procedure leaves critical files open to manipulation by any authenticated user. An attacker can leverage this vulnerability to escalate privileges to SYSTEM. Was ZDI-CAN-5097.

Affected configurations

Nvd
Vulners
Node
hitachienergysys600_firmwareMatch9.0
OR
hitachienergysys600_firmwareMatch9.1
OR
hitachienergysys600_firmwareMatch9.1.5
OR
hitachienergysys600_firmwareMatch9.2
OR
hitachienergysys600_firmwareMatch9.4
AND
hitachienergysys600Match-
VendorProductVersionCPE
hitachienergysys600_firmware9.0cpe:2.3:o:hitachienergy:sys600_firmware:9.0:*:*:*:*:*:*:*
hitachienergysys600_firmware9.1cpe:2.3:o:hitachienergy:sys600_firmware:9.1:*:*:*:*:*:*:*
hitachienergysys600_firmware9.1.5cpe:2.3:o:hitachienergy:sys600_firmware:9.1.5:*:*:*:*:*:*:*
hitachienergysys600_firmware9.2cpe:2.3:o:hitachienergy:sys600_firmware:9.2:*:*:*:*:*:*:*
hitachienergysys600_firmware9.4cpe:2.3:o:hitachienergy:sys600_firmware:9.4:*:*:*:*:*:*:*
hitachienergysys600-cpe:2.3:h:hitachienergy:sys600:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "ABB MicroSCADA",
    "vendor": "ABB",
    "versions": [
      {
        "status": "affected",
        "version": "9.3 with FP 1-2-3"
      }
    ]
  }
]

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

23.4%

Related for CVE-2018-1168