PT-2024-19188 · Elspec · Elspec G5 Digital Fault Recorder

Benedikt Kühne

+1

·

Published

2024-03-19

·

Updated

2024-08-03

·

CVE-2024-22078

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Elspec G5 digital fault recorder versions 1.1.4.15 and before
Description An issue in the Elspec G5 digital fault recorder allows privilege escalation via world writable files. The network configuration script has weak filesystem permissions, resulting in write access for all authenticated users and the possibility to escalate from user privileges to administrative privileges.
Recommendations For Elspec G5 digital fault recorder versions 1.1.4.15 and before, consider restricting write access to the network configuration script to prevent privilege escalation until a patch is available. As a temporary workaround, review and adjust the filesystem permissions to limit access to authorized users only.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-22078

Affected Products

Elspec G5 Digital Fault Recorder