PT-2022-15491 · Miele · Miele Benchmark Programming Tool

J. Kruchem

+1

·

Published

2022-04-27

·

Updated

2024-09-16

·

CVE-2022-22521

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Miele Benchmark Programming Tool versions prior to 1.2.71
Description The issue allows executable files manipulated by attackers to be unknowingly executed with user privileges. An attacker with low privileges may trick a user with administrative privileges to execute these binaries as admin, potentially obtaining higher permissions. The attacker must already have access to the corresponding local system to exchange the files.
Recommendations For versions prior to 1.2.71, update to version 1.2.71 or later to resolve the issue. As a temporary workaround, consider restricting access to executable files and limiting user privileges to minimize the risk of exploitation.

Exploit

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2022-22521

Affected Products

Miele Benchmark Programming Tool