CVE Vulnerabilities

CVE-2024-8306

Improper Privilege Management

Published: Sep 11, 2024 | Modified: Sep 18, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries to perform privilege escalation by tampering with the binaries.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Vijeo_designer Schneider-electric * 6.3 (excluding)
Vijeo_designer Schneider-electric 6.3 (including) 6.3 (including)
Vijeo_designer_embedded_in_ecostruxure_machine_expert Schneider-electric * *

Potential Mitigations

References