← volver
CVE-2018-1168

CVE-2018-1168

EPSS 0.3%CWE-284
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
21 feb 2018Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB MicroSCADA 9.3 with FP 1-2-3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of the access controls for the installed product files. The installation procedure leaves critical files open to manipulation by any authenticated user. An attacker can leverage this vulnerability to escalate privileges to SYSTEM. Was ZDI-CAN-5097.
Productos afectados
ABB · ABB MicroSCADA

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →