PT-2024-8722 · Siport · Siport

Published

2024-11-12

·

Updated

2024-11-17

·

CVE-2024-47783

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SIPORT versions prior to V3.4.0
Description A vulnerability has been identified in the affected application, which improperly assigns file permissions to installation folders. This could allow a local attacker with an unprivileged account to override or modify the service executables and subsequently gain elevated privileges. The vulnerability is related to the improper assignment of permissions for critical resources, which can be exploited to elevate privileges.
Recommendations For versions prior to V3.4.0, update to version V3.4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the installation folders to prevent modification of service executables. Additionally, monitor system activity for any suspicious changes to file permissions or service executables.

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2024-10325
CVE-2024-47783

Affected Products

Siport