7.3

CVE-2022-22521

Exploit

Privilege Escalation in Miele Benchmark Programming Tool

In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users privileges. An attacker with low privileges may trick a user with administrative privileges to execute these binaries as admin.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MieleBenchmark Programming Tool Version < 1.2.72
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.52% 0.4
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
nvd@nist.gov 7.3 1.3 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
info@cert.vde.com 7.3 1.3 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE-732 Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

http://packetstormsecurity.com/files/166881/Miele-Benchmark-Programming-Tool-1.1.49-1.2.71-Privilege-Escalation.html
Patch
Third Party Advisory
Exploit
VDB Entry
http://seclists.org/fulldisclosure/2022/Apr/42
Patch
Third Party Advisory
Exploit
Mailing List
https://cert.vde.com/en/advisories/VDE-2022-015/
Third Party Advisory
Mitigation
https://www.miele.de/p/miele-benchmark-programming-tool-2296.htm
Patch
Vendor Advisory
Product
Release Notes