Lucene search

K
nvd[email protected]NVD:CVE-2024-5622
HistoryAug 29, 2024 - 11:15 a.m.

CVE-2024-5622

2024-08-2911:15:27
CWE-250
CWE-426
CWE-267
web.nvd.nist.gov
1
untrusted search path
aprolconfigureccservices
b&r aprol
local attacker
arbitrary code
elevated privileges

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

9.6%

An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may allow an authenticated local attacker to execute arbitrary code with elevated privileges.

Affected configurations

Nvd
Node
br-automationindustrial_automation_aprolRanger4.2-07p3
OR
br-automationindustrial_automation_aprolRanger4.3-00p3r4.4-00p3
VendorProductVersionCPE
br-automationindustrial_automation_aprol*cpe:2.3:a:br-automation:industrial_automation_aprol:*:*:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

9.6%

Related for NVD:CVE-2024-5622