Privilege escalation in AVEVA Edge - CVE-2017-7968

 

Privilege escalation in AVEVA Edge - CVE-2017-7968

Published: May 19, 2017


Vulnerability identifier: #VU6607
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7968
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists due to insufficient permissions that are set on files and directories in the system's path. A local attacker can
use Wonderware InduSoft Web Studio installation to write and execute malicious files to gain root privileges.

Successful exploitation of the vulnerability results in privilege escalation.





Affected software

AVEVA Edge

How to mitigate CVE-2017-7968

Install update from vendor's website.


External References

Related Security Bulletins