Lucene search

K
cvelistIcscertCVELIST:CVE-2022-3263
HistorySep 23, 2022 - 6:30 p.m.

CVE-2022-3263 Measuresoft ScadaPro Server Improper Access Control

2022-09-2318:30:36
CWE-284
icscert
www.cve.org
1
measuresoft scadapro
improper access control
version 6.7
cve-2022-3263
local user
limited privileges
inconsistent permissions
service binary path
system privileges

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0.001

Percentile

16.2%

The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modify the service binary path and start malicious commands with SYSTEM privileges.

CNA Affected

[
  {
    "product": "ScadaPro Server",
    "vendor": "Measuresoft",
    "versions": [
      {
        "status": "affected",
        "version": "6.7"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0.001

Percentile

16.2%

Related for CVELIST:CVE-2022-3263