PT-2018-1571 · Honeywell · Cn51+13

Publicado

2018-09-11

·

Atualizado

2019-10-09

·

CVE-2018-14825

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions Honeywell Mobile Computers CT60 versions 7.1 Honeywell Mobile Computers CN80 versions 7.1 Honeywell Mobile Computers CT40 versions 7.1 Honeywell Mobile Computers CK75 versions 6.0 Honeywell Mobile Computers CN75 versions 6.0 Honeywell Mobile Computers CN75e versions 6.0 Honeywell Mobile Computers CT50 versions 6.0 Honeywell Mobile Computers D75e versions 6.0 Honeywell Mobile Computers CT50 versions 4.4 Honeywell Mobile Computers D75e versions 4.4 Honeywell Mobile Computers CN51 versions 6.0 Honeywell Mobile Computers EDA50k versions 4.4 Honeywell Mobile Computers EDA50 versions 7.1 Honeywell Mobile Computers EDA50k versions 7.1 Honeywell Mobile Computers EDA70 versions 7.1 Honeywell Mobile Computers EDA60k versions 7.1 Honeywell Mobile Computers EDA51 versions 8.1
Description The issue is related to privilege management errors in the operating system of Honeywell industrial portable computers. Exploitation of this issue could allow a remote attacker to elevate their privileges using a specially crafted application. This could enable the attacker to obtain access to sensitive information such as keystrokes, passwords, personal identifiable information, photos, emails, or business-critical documents.
Recommendations For CT60 version 7.1, update the operating system to a version that includes the fix for this issue. For CN80 version 7.1, update the operating system to a version that includes the fix for this issue. For CT40 version 7.1, update the operating system to a version that includes the fix for this issue. For CK75 version 6.0, update the operating system to a version that includes the fix for this issue. For CN75 version 6.0, update the operating system to a version that includes the fix for this issue. For CN75e version 6.0, update the operating system to a version that includes the fix for this issue. For CT50 version 6.0, update the operating system to a version that includes the fix for this issue. For D75e version 6.0, update the operating system to a version that includes the fix for this issue. For CT50 version 4.4, update the operating system to a version that includes the fix for this issue. For D75e version 4.4, update the operating system to a version that includes the fix for this issue. For CN51 version 6.0, update the operating system to a version that includes the fix for this issue. For EDA50k version 4.4, update the operating system to a version that includes the fix for this issue. For EDA50 version 7.1, update the operating system to a version that includes the fix for this issue. For EDA50k version 7.1, update the operating system to a version that includes the fix for this issue. For EDA70 version 7.1, update the operating system to a version that includes the fix for this issue. For EDA60k version 7.1, update the operating system to a version that includes the fix for this issue. For EDA51 version 8.1, update the operating system to a version that includes the fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-01128
CVE-2018-14825

Produtos afetados

Ck75
Cn51
Cn75
Cn75E
Cn80
Ct40
Ct50
Ct60
D75E
Eda50
Eda50K
Eda51
Eda60K
Eda70