7.8

CVE-2024-1156

Exploit

Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges.

Data is provided by the National Vulnerability Database (NVD)
EmersonData Record Ad Version <= 2.0.1
EmersonFlexlogger Version <= 2022_q3
EmersonG Web Development Software Version <= 2022_q3
EmersonLabview Nxg Version5.1 SwEditioncommunity
EmersonLabview Nxg Version5.1 SwEditionreal-time_module
EmersonLabview Nxg Version5.1 SwEditionweb_module
EmersonSts Software Bundle Version <= 21.0
EmersonSystemlink Server Version < 2024_q1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.14% 0.344
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security@ni.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.