PT-2002-2645 · Schneider Electric · Powerchute Plus
Publicado
2002-12-31
·
Atualizado
2008-09-05
·
CVE-2002-1924
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
PowerChute plus version 5.0.2
Description
The issue concerns the creation of a shared and world-writable "Pwrchute" directory during the installation of the affected software, potentially allowing remote attackers to modify or create files within this directory.
Recommendations
For PowerChute plus version 5.0.2, consider restricting access to the "Pwrchute" directory to prevent unauthorized modifications or file creations until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Powerchute Plus