PT-2018-16890 · Rapid Scada · Rapid Scada

Filipe Xavier Oliveira

·

Published

2018-03-08

·

Updated

2020-08-24

·

CVE-2018-5313

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rapid Scada version 5.5.0
Description A local attacker can escalate privileges due to weak access control restrictions set during the installation of the product. The vulnerability exists within the access control and allows an attacker to execute arbitrary code under the context of Administrator, the IUSR account, or SYSTEM.
Recommendations For Rapid Scada version 5.5.0, consider restricting access to the C:SCADA directory to prevent exploitation until a patch is available. As a temporary workaround, review and modify the access control settings to enforce stronger permissions, limiting the ability of attackers to leverage this flaw for privilege escalation.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-5313

Affected Products

Rapid Scada