Schweitzer Engineering Laboratories (SEL) AcSELerator QuickSet before 5.12.0.1 uses weak permissions for its Program Files directory, which allows local users to replace executable files, and consequently gain privileges, via standard filesystem operations.
References
Link | Resource |
---|---|
http://ics-cert.us-cert.gov/pdf/ICSA-13-079-01.pdf | US Government Resource |
Configurations
Information
Published : 2013-03-21 07:55
Updated : 2013-03-21 14:04
NVD link : CVE-2013-0665
Mitre link : CVE-2013-0665
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
selinc
- acselerator_quickset