PT-2023-4690 · Unknown · Sicam Toolbox Ii

CVE-2023-38641

·

Publicado

2023-08-08

·

Atualizado

2023-08-15

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SICAM TOOLBOX II versions prior to V07.10
Description A vulnerability has been identified in the SICAM TOOLBOX II application, where the database service is executed as NT AUTHORITYSYSTEM. This could allow a local attacker to execute operating system commands with elevated privileges. The issue is related to access control errors, which may enable an attacker to execute arbitrary commands with increased privileges.
Recommendations For versions prior to V07.10, update to version V07.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the database service to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-05110
CVE-2023-38641

Produtos afetados

Sicam Toolbox Ii