CVE Vulnerabilities

CVE-2024-8306

Improper Privilege Management

Published: Sep 11, 2024 | Modified: Sep 18, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries to perform privilege escalation by tampering with the binaries.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Vijeo_designerSchneider-electric*6.3 (excluding)
Vijeo_designerSchneider-electric6.3 (including)6.3 (including)
Vijeo_designer_embedded_in_ecostruxure_machine_expertSchneider-electric**

Potential Mitigations

References