Lucene search

K
cveMitreCVE-2024-25086
HistoryJul 02, 2024 - 4:15 p.m.

CVE-2024-25086

2024-07-0216:15:04
CWE-269
CWE-94
mitre
web.nvd.nist.gov
26
cve-2024-25086
improper privilege management
local attackers
arbitrary code execution

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0

Percentile

5.3%

Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code.

Affected configurations

Nvd
Node
jungowindriverRange<12.2.0
Node
mitsubishielectriccpu_module_logging_configuration_tool
OR
mitsubishielectriccw_configurator
OR
mitsubishielectricdata_transfer
OR
mitsubishielectricdata_transfer_classic
OR
mitsubishielectricezsocket
OR
mitsubishielectricfr_configurator_sw3
OR
mitsubishielectricfr_configurator2
OR
mitsubishielectricgenesis64
OR
mitsubishielectricgt_got1000
OR
mitsubishielectricgt_got2000
OR
mitsubishielectricgt_softgot1000
OR
mitsubishielectricgt_softgot2000
OR
mitsubishielectricgx_developer
OR
mitsubishielectricgx_logviewer
OR
mitsubishielectricgx_works2
OR
mitsubishielectricgx_works3
OR
mitsubishielectriciq_works
OR
mitsubishielectricmi_configurator
OR
mitsubishielectricmr_configurator
OR
mitsubishielectricmr_configurator2
OR
mitsubishielectricmx_component
OR
mitsubishielectricmx_opc_server_da\/ua
OR
mitsubishielectricnumerical_control_device_communication
OR
mitsubishielectricpx_developer\/monitor_tool
OR
mitsubishielectricrt_toolbox3
OR
mitsubishielectricrt_visualbox
Node
mitsubishielectricmrzjw3-mc2-utl_firmware
AND
mitsubishielectricmrzjw3-mc2-utlMatch-
Node
mitsubishielectricsw0dnc-mneth-b_firmware
AND
mitsubishielectricsw0dnc-mneth-bMatch-
Node
mitsubishielectricsw1dnc-ccbd2-b_firmware
AND
mitsubishielectricsw1dnc-ccbd2-bMatch-
Node
mitsubishielectricsw1dnc-ccief-j_firmware
AND
mitsubishielectricsw1dnc-ccief-jMatch-
Node
mitsubishielectricsw1dnc-ccief-b_firmware
AND
mitsubishielectricsw1dnc-ccief-bMatch-
Node
mitsubishielectricsw1dnc-mnetg-b_firmware
AND
mitsubishielectricsw1dnc-mnetg-bMatch-
Node
mitsubishielectricsw1dnc-qsccf-b_firmware
AND
mitsubishielectricsw1dnc-qsccf-bMatch-
Node
mitsubishielectricsw1dnd-emsdk-b_firmware
AND
mitsubishielectricsw1dnd-emsdk-bMatch-
VendorProductVersionCPE
jungowindriver*cpe:2.3:a:jungo:windriver:*:*:*:*:*:*:*:*
mitsubishielectriccpu_module_logging_configuration_tool*cpe:2.3:a:mitsubishielectric:cpu_module_logging_configuration_tool:*:*:*:*:*:*:*:*
mitsubishielectriccw_configurator*cpe:2.3:a:mitsubishielectric:cw_configurator:*:*:*:*:*:*:*:*
mitsubishielectricdata_transfer*cpe:2.3:a:mitsubishielectric:data_transfer:*:*:*:*:*:*:*:*
mitsubishielectricdata_transfer_classic*cpe:2.3:a:mitsubishielectric:data_transfer_classic:*:*:*:*:*:*:*:*
mitsubishielectricezsocket*cpe:2.3:a:mitsubishielectric:ezsocket:*:*:*:*:*:*:*:*
mitsubishielectricfr_configurator_sw3*cpe:2.3:a:mitsubishielectric:fr_configurator_sw3:*:*:*:*:*:*:*:*
mitsubishielectricfr_configurator2*cpe:2.3:a:mitsubishielectric:fr_configurator2:*:*:*:*:*:*:*:*
mitsubishielectricgenesis64*cpe:2.3:a:mitsubishielectric:genesis64:*:*:*:*:*:*:*:*
mitsubishielectricgt_got1000*cpe:2.3:a:mitsubishielectric:gt_got1000:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 431

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0

Percentile

5.3%

Related for CVE-2024-25086