PT-2021-6938 · Advantech · Advantech R-Seenet

Yuri Kramarz

·

Published

2021-08-23

·

Updated

2022-06-29

·

CVE-2021-21910

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advantech R-SeeNet version 2.4.15
Description A privilege escalation issue exists due to insufficient access restrictions to the C:R-SeeNet directory. This can be exploited by an attacker using a specially crafted malicious file to elevate privileges to NT SYSTEM authority.
Recommendations For Advantech R-SeeNet version 2.4.15, consider restricting access to the C:R-SeeNet directory to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the vulnerable directory for executing files from untrusted sources.

Exploit

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02702
CVE-2021-21910

Affected Products

Advantech R-Seenet