7.8

CVE-2024-1155

Exploit

Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access. 

Data is provided by the National Vulnerability Database (NVD)
EmersonData Record Ad Version <= 2.0.1
EmersonFlexlogger Version <= 2022_q3
EmersonG Web Development Software Version <= 2022_q3
EmersonLabview Nxg Version5.1 SwEditioncommunity
EmersonLabview Nxg Version5.1 SwEditionreal-time_module
EmersonLabview Nxg Version5.1 SwEditionweb_module
EmersonSts Software Bundle Version <= 21.0
EmersonSystemlink Server Version < 2024_q1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.11% 0.298
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security@ni.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.