PT-2024-8722 · Siport · Siport
Published
2024-11-12
·
Updated
2024-11-17
·
CVE-2024-47783
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SIPORT versions prior to V3.4.0
Description
A vulnerability has been identified in the affected application, which improperly assigns file permissions to installation folders. This could allow a local attacker with an unprivileged account to override or modify the service executables and subsequently gain elevated privileges. The vulnerability is related to the improper assignment of permissions for critical resources, which can be exploited to elevate privileges.
Recommendations
For versions prior to V3.4.0, update to version V3.4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the installation folders to prevent modification of service executables. Additionally, monitor system activity for any suspicious changes to file permissions or service executables.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siport