A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a local user to execute processes that otherwise require escalation privileges when sending local network commands to the IGSS Update Service.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://www.se.com/ww/en/download/document/SEVD-2020-070-01/ | vendor advisory |
https://www.zerodayinitiative.com/advisories/ZDI-20-370/ | vdb entry third party advisory |