Lucene search

K
cvelistTalosCVELIST:CVE-2020-13551
HistoryFeb 17, 2021 - 6:17 p.m.

CVE-2020-13551

2021-02-1718:17:14
CWE-276
talos
www.cve.org
4
vulnerability
file system permissions
advantech webaccess/scada 9.0.1
local privilege escalation
postgresql
nt system privilege

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

20.3%

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via PostgreSQL executable, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.

CNA Affected

[
  {
    "product": "Advantech",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Advantech WebAccess/SCADA 9.0.1"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

20.3%

Related for CVELIST:CVE-2020-13551