PT-2018-10744 · Abb · Abb Microscada
Fritz Sands
·
Published
2017-08-18
·
Updated
2023-05-16
·
CVE-2018-1168
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ABB MicroSCADA versions 9.3 with FP 1-2-3
Description
This issue allows local attackers to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this issue. The specific flaw exists within the configuration of the access controls for the installed product files. The installation procedure leaves critical files open to manipulation by any authenticated user. An attacker can leverage this issue to escalate privileges to SYSTEM.
Recommendations
For ABB MicroSCADA versions 9.3 with FP 1-2-3, consider restricting access to the critical files that are left open to manipulation by any authenticated user until a patch is available. As a temporary workaround, limit the privileges of authenticated users to minimize the risk of exploitation.
Fix
Incorrect Permission
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Abb Microscada