Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r578-gc8q-v9ww

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An Externally Controlled Reference to a Resource (CWE-610) vulnerability exists in Schneider Electric Modbus Serial Driver (For 64-bit Windows OS:V3.17 IE 37 and prior , For 32-bit Windows OS:V2.17 IE 27 and prior, and as part of the Driver Suite version:V14.12 and prior) which could allow write access to system files available only to users with SYSTEM privilege or other important user files.

An Externally Controlled Reference to a Resource (CWE-610) vulnerability exists in Schneider Electric Modbus Serial Driver (For 64-bit Windows OS:V3.17 IE 37 and prior , For 32-bit Windows OS:V2.17 IE 27 and prior, and as part of the Driver Suite version:V14.12 and prior) which could allow write access to system files available only to users with SYSTEM privilege or other important user files.

EPSS

Процентиль: 41%
0.00191
Низкий

Связанные уязвимости

CVSS3: 4.9
nvd
больше 6 лет назад

An Externally Controlled Reference to a Resource (CWE-610) vulnerability exists in Schneider Electric Modbus Serial Driver (For 64-bit Windows OS:V3.17 IE 37 and prior , For 32-bit Windows OS:V2.17 IE 27 and prior, and as part of the Driver Suite version:V14.12 and prior) which could allow write access to system files available only to users with SYSTEM privilege or other important user files.

CVSS3: 7.8
fstec
почти 7 лет назад

Уязвимость драйвера программируемых логических контроллеров Schneider Electric Modbus Serial Driver, связанная с ошибками при обработке гипертекстовых ссылок, позволяющая нарушителю перезаписать файлы в файловой системе

EPSS

Процентиль: 41%
0.00191
Низкий