PT-2022-6659 · Measuresoft · Measuresoft Scadapro Server
Rgod777
·
Published
2022-09-22
·
Updated
2022-09-27
·
CVE-2022-3263
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Measuresoft ScadaPro Server version 6.7
Description
The issue is related to improper access control in the security descriptor of the SCADA server, which could allow a local user with limited privileges to modify the service binary path. This could enable an attacker to execute arbitrary commands with system privileges.
Recommendations
For Measuresoft ScadaPro Server version 6.7, consider restricting access to the service binary path to prevent modification and limit the execution of malicious commands until a patch is available. As a temporary workaround, review and enforce strict access controls on the system to minimize the risk of exploitation.
Fix
Improper Access Control
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Measuresoft Scadapro Server