PT-2022-6544 · Scada-Lts · Scada-Lts
M3N0Sd0N4Ld
·
Published
2022-08-29
·
Updated
2023-04-14
·
CVE-2022-41976
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Scada-LTS version 2.7.1.1 build 2948559113
Description
A privilege escalation issue was discovered that allows remote attackers, authenticated in the application as a low-privileged user, to change their role, for example, to administrator, by updating their user profile. This issue is related to authorization errors.
Recommendations
For Scada-LTS version 2.7.1.1 build 2948559113, consider restricting access to user profile updates until a patch is available. As a temporary workaround, limit the ability of low-privileged users to modify their roles or access levels.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scada-Lts