Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of privilege and provide full access control to local system users to SoMove component and services when a SoMove installer script is launched.
oryginał ENCVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSchneider Electric Somove
APPSchneider-Electric≤ 2.8.1
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Powiązane podatności
CVE-2018-7239HIGH7.8ten sam produkt
A DLL hijacking vulnerability exists in Schneider Electric's SoMove Software and associated DTM software compo...
CVE-2014-9200HIGH7.5ten sam produkt
Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electric Unity Pr...
CVE-2013-0662HIGH9.3ten sam produkt
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through...
CVE-2018-7841CRITICAL9.8⚠ KEVPL ✓ten sam vendor
SQL Injection z RCE w Schneider Electric U.Motion Builder 1.3.4
CVE-2024-10575CRITICAL10.0PL ✓ten sam vendor
Brak autoryzacji w Schneider Electric EcoStruxure IT Gateway (CVSS 10.0)