Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gv63-8gqg-3525

Опубликовано: 16 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 1.8
CVSS3: 5.5

Описание

An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up or restore process, which temporarily exposes private keys, passwords, pre-shared keys, and database folders when they are temporarily copied to an interim folder. This vulnerability is due to the lack of explicit permissions set on the backup folder. If private keys are obtained by a malicious user, they could impersonate resources on the secured network.

An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up or restore process, which temporarily exposes private keys, passwords, pre-shared keys, and database folders when they are temporarily copied to an interim folder. This vulnerability is due to the lack of explicit permissions set on the backup folder. If private keys are obtained by a malicious user, they could impersonate resources on the secured network.

EPSS

Процентиль: 1%
0.00008
Низкий

1.8 Low

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-269
CWE-276

Связанные уязвимости

CVSS3: 5.5
nvd
больше 1 года назад

An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up or restore process, which temporarily exposes private keys, passwords, pre-shared keys, and database folders when they are temporarily copied to an interim folder. This vulnerability is due to the lack of explicit permissions set on the backup folder. If private keys are obtained by a malicious user, they could impersonate resources on the secured network.

CVSS3: 5.9
fstec
больше 1 года назад

Уязвимость системной службы FactoryTalk System Services программного обеспечения управления производственными процессами FactoryTalk Policy Manager, связанная с недостатками разграничения доступа, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 1%
0.00008
Низкий

1.8 Low

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-269
CWE-276