7.8

CVE-2024-1155

Exploit

Incorrect permissions for shared NI SystemLink Elixir based services

Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access. 
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Emerson ≫ Data Record Ad Version <= 2.0.1
Emerson ≫ Flexlogger Version <= 2022_q3
Emerson ≫ G Web Development Software Version <= 2022_q3
Emerson ≫ Labview Nxg Version 5.1 SwEdition community
Emerson ≫ Labview Nxg Version 5.1 SwEdition real-time_module
Emerson ≫ Labview Nxg Version 5.1 SwEdition web_module
Emerson ≫ Sts Software Bundle Version <= 21.0
Emerson ≫ Systemlink Server Version < 2024_q1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.189
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security@ni.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/incorrect-permissions-for-shared-systemlink-elixir-based-service.html
Vendor Advisory
Exploit