CVE-2024-1156
20.02.2024, 15:15
Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges.Enginsight
Vendor | Product | Version |
---|---|---|
emerson | data_record_ad | 𝑥 ≤ 2.0.1 |
emerson | flexlogger | 𝑥 ≤ 2022_q3 |
emerson | g_web_development_software | 𝑥 ≤ 2022_q3 |
emerson | labview_nxg | 5.1 |
emerson | labview_nxg | 5.1 |
emerson | labview_nxg | 5.1 |
emerson | specification_compliance_manager | 𝑥 ≤ 2023_q4 |
emerson | static_test_software_suite | 𝑥 ≤ 1.2 |
emerson | sts_software_bundle | 𝑥 ≤ 21.0 |
emerson | systemlink_server | 𝑥 < 2024_q1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-276 - Incorrect Default PermissionsDuring installation, installed file permissions are set to allow anyone to modify those files.
- CWE-863 - Incorrect AuthorizationThe software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
References