PT-2025-6700 · Txone Networks · Stellarenforce+2
Ramya Shah
+2
·
Published
2025-02-17
·
Updated
2025-02-17
·
CVE-2024-47935
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
StellarProtect (Legacy Mode) versions prior to 3.2
StellarEnforce versions prior to 3.2
Safe Lock versions 3.0.0 through 3.1.1076
Description
The issue is related to improper validation of the integrity check value in TXOne Networks products, allowing an attacker to escalate their privileges on the victim's device. The attacker must hijack the DLL file in advance.
Recommendations
For StellarProtect (Legacy Mode) versions prior to 3.2, update to version 3.2 or later.
For StellarEnforce versions prior to 3.2, update to version 3.2 or later.
For Safe Lock versions 3.0.0 through 3.1.1076, update to a version later than 3.1.1076.
As a temporary workaround, consider restricting access to the DLL file to minimize the risk of exploitation.
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Safe Lock
Stellarenforce
Stellarprotect