CVE-2024-1156Incorrect Default Permissions in Systemlink Server

Severity
7.8HIGHNVD
EPSS
0.1%
top 76.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 20

Description

Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages10 packages

CVEListV5ni/flexlogger2022 Q3
NVDemerson/flexlogger2022_q3
CVEListV5ni/systemlink_server2023 Q3

🔴Vulnerability Details

1
GHSA
GHSA-ccq4-9qhm-55xx: Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and2024-02-20
CVE-2024-1156 — Incorrect Default Permissions | cvebase