PT-2022-3959 · Advantech · Advantech Deviceon/Iservice
Yuri Kramarz
·
Published
2022-01-18
·
Updated
2022-05-31
·
CVE-2021-40396
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Advantech DeviceOn/iService version 1.1.7
Description
A privilege escalation issue exists due to incorrect default permission settings, allowing an attacker to elevate privileges using a specially-crafted file. This can be triggered by replacing a file in the system, resulting in escalated privileges to NT SYSTEM authority.
Recommendations
For Advantech DeviceOn/iService version 1.1.7, consider restricting access to sensitive files and directories to prevent unauthorized modifications until a patch is available. As a temporary workaround, monitor system file integrity and access logs closely to detect potential exploitation attempts.
Exploit
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Advantech Deviceon/Iservice