TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2024-22078

HIGH
8.8

Beschreibung

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration script has weak filesystem permissions. This results in write access for all authenticated users and the possibility to escalate from user privileges to administrative privileges.

CVE Details

CVSS v3.1 Bewertung8.8
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht3/20/2024
Zuletzt geandert4/16/2025
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

elspec-ltd:g5dfrelspec-ltd:g5dfr_firmware

Schwachen (CWE)

CWE-280

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.