PT-2023-4720 · Unknown · Sicam Toolbox Ii
Published
2023-08-08
·
Updated
2023-08-15
·
CVE-2022-39062
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SICAM TOOLBOX II versions prior to V07.10
Description
A vulnerability has been identified in SICAM TOOLBOX II where affected applications do not properly set permissions for product folders. This could allow an authenticated attacker with low privileges to replace DLLs and conduct a privilege escalation. The issue is related to the improper assignment of permissions for a critical resource, which could allow a remote attacker to access confidential data and elevate their privileges.
Recommendations
For versions prior to V07.10, update to version V07.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the product folders to prevent unauthorized modifications. Additionally, monitor system activity for suspicious behavior and restrict privileges to the lowest level necessary for authenticated users.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sicam Toolbox Ii