PT-2016-2167 · Dallas · Dallas Lock

Publicado

2016-06-03

·

Atualizado

2016-06-03

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dallas Lock version 8.0
Description The issue concerns a lack of access control implementation in the Dallas Lock 8.0 driver, allowing unauthorized access to file system object attributes. An attacker can access a restricted file system object using a specific attribute, $DATA (identifier 0x80), which contains the file's data.
Recommendations For Dallas Lock version 8.0, consider restricting access to the $DATA attribute to minimize the risk of exploitation until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-01520

Produtos afetados

Dallas Lock