A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver installed by the runtime software of EcoStruxureª Operator Terminal Expert.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Operator_terminal_expert_runtime | Schneider-electric | * | 3.1 (excluding) |
Operator_terminal_expert_runtime | Schneider-electric | 3.1 (including) | 3.1 (including) |
Operator_terminal_expert_runtime | Schneider-electric | 3.1-service_pack_1a (including) | 3.1-service_pack_1a (including) |