Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x953-h4jc-jfvq

Опубликовано: 12 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

A vulnerability has been identified in SICAM PQ Analyzer (All versions < V3.18). A service is started by an unquoted registry entry. As there are spaces in this path, attackers with write privilege to those directories might be able to plant executables that will run in place of the legitimate process. Attackers might achieve persistence on the system ("backdoors") or cause a denial of service.

A vulnerability has been identified in SICAM PQ Analyzer (All versions < V3.18). A service is started by an unquoted registry entry. As there are spaces in this path, attackers with write privilege to those directories might be able to plant executables that will run in place of the legitimate process. Attackers might achieve persistence on the system ("backdoors") or cause a denial of service.

EPSS

Процентиль: 64%
0.00473
Низкий

Дефекты

CWE-428

Связанные уязвимости

CVSS3: 8.1
nvd
около 4 лет назад

A vulnerability has been identified in SICAM PQ Analyzer (All versions < V3.18). A service is started by an unquoted registry entry. As there are spaces in this path, attackers with write privilege to those directories might be able to plant executables that will run in place of the legitimate process. Attackers might achieve persistence on the system ("backdoors") or cause a denial of service.

EPSS

Процентиль: 64%
0.00473
Низкий

Дефекты

CWE-428