5.5

CVE-2023-29081

A vulnerability has been reported in Suite Setups built with versions prior to InstallShield 2023 R2. This vulnerability may allow locally authenticated users to cause a Denial of Service (DoS) condition when handling move operations on local, temporary folders.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FlexeraInstallshield Version2016 Update-
FlexeraInstallshield Version2016 Updatesp1
FlexeraInstallshield Version2016 Updatesp2
FlexeraInstallshield Version2017 Update-
FlexeraInstallshield Version2017 Updatesp1
FlexeraInstallshield Version2018 Update-
FlexeraInstallshield Version2018 Updater2
FlexeraInstallshield Version2018 Updatesp1
FlexeraInstallshield Version2019 Update-
FlexeraInstallshield Version2019 Updater2
FlexeraInstallshield Version2019 Updater3
FlexeraInstallshield Version2020 Update-
FlexeraInstallshield Version2020 Updater2
FlexeraInstallshield Version2020 Updater3
FlexeraInstallshield Version2020 Updater3sp1
FlexeraInstallshield Version2021 Updater1
FlexeraInstallshield Version2021 Updater2
FlexeraInstallshield Version2022 Updater1
FlexeraInstallshield Version2022 Updater2
FlexeraInstallshield Version2023 Updater1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.058
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
PSIRT-CNA@flexerasoftware.com 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.