← Zuruck zu CVEs
CVE-2024-22078
HIGH8.8
Beschreibung
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration script has weak filesystem permissions. This results in write access for all authenticated users and the possibility to escalate from user privileges to administrative privileges.
CVE Details
CVSS v3.1 Bewertung8.8
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht3/20/2024
Zuletzt geandert4/16/2025
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
elspec-ltd:g5dfrelspec-ltd:g5dfr_firmware
Schwachen (CWE)
CWE-280
Referenzen
https://www.elspec-ltd.com/support/security-advisories/(cve@mitre.org)
https://www.elspec-ltd.com/support/security-advisories/(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.