CVE Vulnerabilities

CVE-2023-29066

Improper Privilege Management

Published: Nov 28, 2023 | Modified: Dec 05, 2023
CVSS 3.x
3.5
LOW
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The FACSChorus software does not properly assign data access privileges for operating system user accounts. A non-administrative OS account can modify information stored in the local application data folders.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Facschorus Bd 5.0 (including) 5.0 (including)
Facschorus Bd 5.1 (including) 5.1 (including)

Potential Mitigations

References