Privilege escalation in AVEVA Edge - CVE-2017-7968

 

Privilege escalation in AVEVA Edge - CVE-2017-7968

Published: May 19, 2017


Vulnerability identifier: #VU6607
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-7968
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: AVEVA Software, LLC.
Affected software:
AVEVA Edge

Detailed vulnerability description

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists due to insufficient permissions that are set on files and directories in the system's path. A local attacker can
use Wonderware InduSoft Web Studio installation to write and execute malicious files to gain root privileges.

Successful exploitation of the vulnerability results in privilege escalation.





How to mitigate CVE-2017-7968

Install update from vendor's website.

Sources