#VU18809 Insecure filesustem permissions in exacqVision Enterprise System Manager - CVE-2019-7588
Published: June 17, 2019 / Updated: June 18, 2019
exacqVision Enterprise System Manager
Johnson Controls
Description
The vulnerability allows a local attacker to bypass authorization on the target system.
The vulnerability exists due to the software allows by default excessive permissions to directories granted to authorized, low-privilege system accounts. A local authenticated attacker can make application file changes and escalate privilege on the system.