7.8
CVE-2019-12777
- EPSS 0.03%
- Veröffentlicht 07.06.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:23:33
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They replace secure and protected directory permissions (set as default by the underlying operating system) with highly insecure read, write, and execute directory permissions for all users. By default, /usr/local and all of its subdirectories should have permissions set to only allow non-privileged users to read and execute from the tree structure, and to deny users from creating or editing files in this location. The ENTTEC firmware startup script permits all users to read, write, and execute (rwxrwxrwx) from the /usr, /usr/local, /usr/local/dmxis, and /usr/local/bin/ directories.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Enttec ≫ Datagate Mk2 Firmware Version70044 Update05032019-482
Enttec ≫ Storm 24 Firmware Version70044 Update05032019-482
Enttec ≫ Pixelator Firmware Version70044 Update05032019-482
Enttec ≫ E-streamer Mk2 Firmware Version70044 Update05032019-482
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.053 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.