PT-2022-6544 · Scada-Lts · Scada-Lts

M3N0Sd0N4Ld

·

Published

2022-08-29

·

Updated

2023-04-14

·

CVE-2022-41976

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Scada-LTS version 2.7.1.1 build 2948559113
Description A privilege escalation issue was discovered that allows remote attackers, authenticated in the application as a low-privileged user, to change their role, for example, to administrator, by updating their user profile. This issue is related to authorization errors.
Recommendations For Scada-LTS version 2.7.1.1 build 2948559113, consider restricting access to user profile updates until a patch is available. As a temporary workaround, limit the ability of low-privileged users to modify their roles or access levels.

Exploit

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

BDU:2023-02228
CVE-2022-41976

Affected Products

Scada-Lts