8.8
CVE-2018-10604
- EPSS 0.58%
- Veröffentlicht 24.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:38
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
SEL Compass version 3.0.5.1 and prior allows all users full access to the SEL Compass directory, which may allow modification or overwriting of files within the Compass installation folder, resulting in escalation of privilege and/or malicious code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Selinc ≫ Sel Compass Version <= 3.0.5.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.58% | 0.683 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.