CVE-2017-7968

Severity
7.8HIGH
EPSS
0.0%
top 87.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 19
Latest updateMay 13

Description

An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. Upon installation, Wonderware InduSoft Web Studio creates a new directory and two files, which are placed in the system's path and can be manipulated by non-administrators. This could allow an authenticated user to escalate his or her privileges.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5schneider_electric_wonderware_indusoft_web_studioSchneider Electric Wonderware InduSoft Web Studio

🔴Vulnerability Details

2
GHSA
GHSA-366x-vf96-q5vp: An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v82022-05-13
CVEList
CVE-2017-7968: An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v82017-05-19
CVE-2017-7968 (HIGH CVSS 7.8) | An Incorrect Default Permissions is | cvebase.io