PT-2002-2645 · Schneider Electric · Powerchute Plus

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-1924

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PowerChute plus version 5.0.2
Description The issue concerns the creation of a shared and world-writable "Pwrchute" directory during the installation of the affected software, potentially allowing remote attackers to modify or create files within this directory.
Recommendations For PowerChute plus version 5.0.2, consider restricting access to the "Pwrchute" directory to prevent unauthorized modifications or file creations until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1924

Affected Products

Powerchute Plus