Haas Controller version 100.20.000.1110 has insufficient granularity of access control when using the Ethernet Q Commands service. Any user is able to write macros into registers outside of the authorized accessible range. This could allow a user to access privileged resources or resources out of context.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Haas_controller_firmware | Haascnc | 100.20.000.1110 (including) | 100.20.000.1110 (including) |