PT-2018-16890 · Rapid Scada · Rapid Scada
Filipe Xavier Oliveira
·
Published
2018-03-08
·
Updated
2020-08-24
·
CVE-2018-5313
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Rapid Scada version 5.5.0
Description
A local attacker can escalate privileges due to weak access control restrictions set during the installation of the product. The vulnerability exists within the access control and allows an attacker to execute arbitrary code under the context of Administrator, the IUSR account, or SYSTEM.
Recommendations
For Rapid Scada version 5.5.0, consider restricting access to the C:SCADA directory to prevent exploitation until a patch is available. As a temporary workaround, review and modify the access control settings to enforce stronger permissions, limiting the ability of attackers to leverage this flaw for privilege escalation.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rapid Scada