| |
Vulnerability CVE-2020-28392
Published: 2021-02-09
Description: |
A vulnerability has been identified in SIMARIS configuration (All versions). During installation to default target folder, incorrect permissions are configured for the application folder and subfolders which could allow an attacker to gain persistence or potentially escalate privileges should a user with elevated credentials log onto the machine. |
Type:
CWE-276 (Incorrect Default Permissions)
CVSS2 => (AV:L/AC:L/Au:N/C:P/I:P/A:P)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
4.6/10 |
6.4/10 |
3.9/10 |
Exploit range |
Attack complexity |
Authentication |
Local |
Low |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
Partial |
Partial |
References: |
https://cert-portal.siemens.com/productcert/pdf/ssa-794542.pdf
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|