A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default installation sets insecure file permissions that could allow a local attacker to escalate privileges to local administrator.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-589975.pdf | vendor advisory |