TROYANOSYVIRUS
Volver a CVEs

CVE-2024-22078

HIGH
8.8

Descripcion

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration script has weak filesystem permissions. This results in write access for all authenticated users and the possibility to escalate from user privileges to administrative privileges.

Detalles CVE

Puntuacion CVSS v3.18.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado3/20/2024
Ultima modificacion4/16/2025
Fuentenvd
Avistamientos honeypot0

Productos afectados

elspec-ltd:g5dfrelspec-ltd:g5dfr_firmware

Debilidades (CWE)

CWE-280

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.