Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pggr-mph7-ch3v

Опубликовано: 11 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.3
CVSS3: 7

Описание

A vulnerability has been identified in SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions). The affected device do not properly restrict the user permission for the registry key. This could allow an authenticated attacker to load vulnerable drivers into the system leading to privilege escalation or bypassing endpoint protection and other security measures.

A vulnerability has been identified in SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions). The affected device do not properly restrict the user permission for the registry key. This could allow an authenticated attacker to load vulnerable drivers into the system leading to privilege escalation or bypassing endpoint protection and other security measures.

EPSS

Процентиль: 6%
0.00024
Низкий

7.3 High

CVSS4

7 High

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7
nvd
12 месяцев назад

A vulnerability has been identified in SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions). The affected device do not properly restrict the user permission for the registry key. This could allow an authenticated attacker to load vulnerable drivers into the system leading to privilege escalation or bypassing endpoint protection and other security measures.

CVSS3: 7
fstec
12 месяцев назад

Уязвимость микропрограммного обеспечения устройств SIMATIC IPC, связанная с неправильным присвоением разрешений для критичного ресурса, позволяющая нарушителю обойти существующие ограничения безопасности и повысить свои привилегии

EPSS

Процентиль: 6%
0.00024
Низкий

7.3 High

CVSS4

7 High

CVSS3

Дефекты

CWE-732