Описание
A vulnerability has been identified in Siveillance Control (All versions >= V2.8 < V3.1.1). The affected product does not properly check the list of access groups that are assigned to an individual user. This could enable a locally logged on user to gain write privileges for objects where they only have read privileges.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
EPSS
5.5 Medium
CVSS3
Дефекты
Связанные уязвимости
A vulnerability has been identified in Siveillance Control (All versions >= V2.8 < V3.1.1). The affected product does not properly check the list of access groups that are assigned to an individual user. This could enable a locally logged on user to gain write privileges for objects where they only have read privileges.
Уязвимость программного средства управления и контроля систем видеонаблюдения и безопасности Siemens Siveillance Control, связанная с недостатками механизма авторизации, позволяющая нарушителю получить права на запись для объектов, к которым у него были только права на чтение
EPSS
5.5 Medium
CVSS3