CVE-2024-1155Incorrect Default Permissions in Systemlink Server

Severity
7.8HIGHNVD
EPSS
0.1%
top 75.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 20

Description

Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages10 packages

CVEListV5ni/systemlink_server2023 Q3
CVEListV5ni/flexlogger2022 Q3
NVDemerson/flexlogger2022_q3

🔴Vulnerability Details

1
GHSA
GHSA-3hwp-p2jw-j4xh: Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enabl2024-02-20
CVE-2024-1155 — Incorrect Default Permissions | cvebase