PT-2022-3959 · Advantech · Advantech Deviceon/Iservice

Yuri Kramarz

·

Published

2022-01-18

·

Updated

2022-05-31

·

CVE-2021-40396

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advantech DeviceOn/iService version 1.1.7
Description A privilege escalation issue exists due to incorrect default permission settings, allowing an attacker to elevate privileges using a specially-crafted file. This can be triggered by replacing a file in the system, resulting in escalated privileges to NT SYSTEM authority.
Recommendations For Advantech DeviceOn/iService version 1.1.7, consider restricting access to sensitive files and directories to prevent unauthorized modifications until a patch is available. As a temporary workaround, monitor system file integrity and access logs closely to detect potential exploitation attempts.

Exploit

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04791
CVE-2021-40396

Affected Products

Advantech Deviceon/Iservice