Lucene search

K
cvelistSEC-VLabCVELIST:CVE-2024-36495
HistoryJun 24, 2024 - 8:50 a.m.

CVE-2024-36495 Read/Write Permissions for Everyone on Configuration File

2024-06-2408:50:07
CWE-276
SEC-VLab
www.cve.org
3
cve
configuration file
faronics winselect
read/write
everyone
file system
access control

0.0004 Low

EPSS

Percentile

15.8%

The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file system which “Everyone” has read and write access to, path to file:

C:\ProgramData\WINSelect\WINSelect.wsd

The path for the affected WINSelect Enterprise configuration file is:

C:\ProgramData\Faronics\StorageSpace\WS\WINSelect.wsd

CNA Affected

[
  {
    "defaultStatus": "affected",
    "product": "WINSelect (Standard + Enterprise)",
    "vendor": "Faronics",
    "versions": [
      {
        "status": "unaffected",
        "version": "8.30.xx.903",
        "versionType": "custom"
      }
    ]
  }
]

0.0004 Low

EPSS

Percentile

15.8%

Related for CVELIST:CVE-2024-36495