The EAI developed by Digiwin has a Privilege Escalation vulnerability, allowing remote attackers with regular privileges to elevate their privileges to administrator level via a specific API.
Solution:
The product does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly.
Link | Tags |
---|---|
https://www.twcert.org.tw/tw/cp-132-10272-5b691-1.html | third party advisory |
https://www.twcert.org.tw/en/cp-139-10273-ce2ed-2.html | third party advisory |
https://www.digiwin.com/tw/news/3567.html | vendor advisory |