Vulnerability CVE-2018-15809


Published: 2018-08-23

Description:
AccuPOS 2017.8 is installed with the insecure "Authenticated Users: Modify" permission for files within the installation path. This may allow local attackers to compromise the integrity of critical resource and executable files.

Type:

CWE-284

(Improper Access Control)

Vendor: Accupos
Product: Accupos 
Version: 2017.8;

CVSS2 => (AV:L/AC:L/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None

 References:
https://versprite.com/advisories/accupos/

Copyright 2019, cxsecurity.com

 

Back to Top