CVE Vulnerabilities

CVE-2023-29066

Incorrect Privilege Assignment

Published: Nov 28, 2023 | Modified: Nov 21, 2024
CVSS 3.x
3.5
LOW
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The FACSChorus software does not properly assign data access privileges for operating system user accounts. A non-administrative OS account can modify information stored in the local application data folders.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Facschorus Bd 5.0 (including) 5.0 (including)
Facschorus Bd 5.1 (including) 5.1 (including)

Potential Mitigations

References