PT-2006-6628 · Passgo Technologies · Passgo Sso Plus
Published
2006-11-26
·
Updated
2018-10-17
·
CVE-2006-5965
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PassGo SSO Plus versions 2.1.0.32 and earlier
Description
The issue allows local users to gain privileges by modifying critical programs due to insecure permissions set for the PassGo Technologies directory, which has Everyone/Full Control settings.
Recommendations
For PassGo SSO Plus versions 2.1.0.32 and earlier, consider changing the permissions of the PassGo Technologies directory to restrict access and prevent local users from modifying critical programs.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Passgo Sso Plus