PT-2020-2738 · Emerson · Openenterprise
Roman Lozko
·
Published
2020-05-20
·
Updated
2022-03-07
·
CVE-2020-10632
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Emerson OpenEnterprise versions through 3.3.4
Description
The issue is related to inadequate folder security permissions, which may allow modification of important configuration files. This could cause the system to fail or behave in an unpredictable manner. An attacker, acting remotely, could exploit this to cause a denial of service.
Recommendations
For Emerson OpenEnterprise versions through 3.3.4, consider restricting access to important configuration files to prevent unauthorized modifications until a patch is available. As a temporary workaround, review and tighten folder security permissions to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openenterprise