PT-2016-2167 · Dallas · Dallas Lock

Published

2016-06-03

·

Updated

2016-06-03

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dallas Lock version 8.0
Description The issue concerns a lack of access control implementation in the Dallas Lock 8.0 driver, allowing unauthorized access to file system object attributes. An attacker can access a restricted file system object using a specific attribute, $DATA (identifier 0x80), which contains the file's data.
Recommendations For Dallas Lock version 8.0, consider restricting access to the $DATA attribute to minimize the risk of exploitation until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01520

Affected Products

Dallas Lock