#VU67599 Improper access control in ScadaPro Server - CVE-2022-3263

 

#VU67599 Improper access control in ScadaPro Server - CVE-2022-3263

Published: September 23, 2022 / Updated: September 27, 2022


Vulnerability identifier: #VU67599
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-3263
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
ScadaPro Server
Software vendor:
Measuresoft

Description

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions within the ORCHESTRATOR Service. A local user can modify the service binary path and start malicious commands with elevated privileges.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links