The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has an Incorrect Default Permissions (CWE-276) vulnerability. The affected product is vulnerable to insufficient default permissions, which could allow an attacker to view network configurations through SNMP communication. This is a different issue than CVE-2019-16879, CVE-2019-20045, CVE-2019-20046, CVE-2020-7800, and CVE-2020-7801.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://www.us-cert.gov/ics/advisories/icsa-20-042-01 | third party advisory us government resource |