Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-22078

Опубликовано: 20 мар. 2024
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration script has weak filesystem permissions. This results in write access for all authenticated users and the possibility to escalate from user privileges to administrative privileges.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:elspec-ltd:g5dfr_firmware:*:*:*:*:*:*:*:*
Версия до 1.2.1.12 (исключая)
cpe:2.3:h:elspec-ltd:g5dfr:-:*:*:*:*:*:*:*

EPSS

Процентиль: 48%
0.00244
Низкий

8.8 High

CVSS3

Дефекты

CWE-280

Связанные уязвимости

CVSS3: 8.8
github
почти 2 года назад

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration script has weak filesystem permissions. This results in write access for all authenticated users and the possibility to escalate from user privileges to administrative privileges.

EPSS

Процентиль: 48%
0.00244
Низкий

8.8 High

CVSS3

Дефекты

CWE-280