CVE-2024-1155
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected (10)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.0.1 | |
| Up to 2022_q3 | |
| Up to 2022_q3 | |
| Version 5.1 | |
| Up to 2023_q4 | |
| Up to 1.2 | |
| Up to 21.0 | |
| Before 2024_q1 |
Related CWEs
CWE-276
Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
CWE-863
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
References (2)
Source: security@ni.com
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory
Timeline
No history available yet.