The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modify the service binary path and start malicious commands with SYSTEM privileges.
Workaround:
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-265-01 | us government resource third party advisory mitigation |