#VU9080 Privilege escalation in VTScada - CVE-2017-14031 

 

#VU9080 Privilege escalation in VTScada - CVE-2017-14031

Published: November 1, 2017


Vulnerability identifier: #VU9080
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/U:Clear
CVE-ID: CVE-2017-14031
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
VTScada
Software vendor:
Trihedral Engineering Ltd

Description

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The vulnerability exists due to improper access control. A local attacker can gain elevated privileges and possibly execute arbitrary code.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Remediation

Update to version 11.3.05.

External links