CVE ID | CVE-2018-1168 |
CVSS SCORE | 6.0, AV:L/AC:H/Au:S/C:C/I:C/A:C |
AFFECTED VENDORS |
ABB |
AFFECTED PRODUCTS |
MicroSCADA |
VULNERABILITY DETAILS |
The specific flaw exists within the configuration of the access controls for the installed product files. The installation procedure leaves critical files open to manipulation by any authenticated user. An attacker can leverage this vulnerability to escalate privileges to SYSTEM. |
ADDITIONAL DETAILS |
ABB has issued an update to correct this vulnerability. More details can be found at:
https://library.e.abb.com/public/7a88a74b12bb492ea138b1f2365d00f6/ABBVU-PGGA-33888_ABB_SoftwareVulnerabilityHandlingAdvisory_Rev_A.pdf?x-sign=MJfu9cHtRUUubpLAYzyWFTmW5W+mg3kZ/nm7F/Jw5HlFTQf4eNyfLAgE8HozRJEC |
DISCLOSURE TIMELINE |
|
CREDIT | Fritz Sands - Trend Micro Zero Day Initiative |