CVE-2013-2786: Medium severity micom s1 agile vulnerability
Published Jul 10, 2013
·Updated
Alstom Grid MiCOM S1 Agile before 1.0.3 and Alstom Grid MiCOM S1 Studio use weak permissions for the MiCOM S1 %PROGRAMFILES% directory, which allows local users to gain privileges via a Trojan horse executable file.
Affected Software
2 affected components
Alstom MiCOM S1 Agile<=1.0.2
Alstom MiCOM S1 Studio
Event History
Jul 10, 2013
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2786?
CVE-2013-2786 has a moderate severity rating due to its ability to allow local users to gain privileges.
2
How do I fix CVE-2013-2786?
To fix CVE-2013-2786, upgrade Alstom Grid MiCOM S1 Agile to version 1.0.3 or later.
3
What systems are affected by CVE-2013-2786?
CVE-2013-2786 affects Alstom Grid MiCOM S1 Agile versions prior to 1.0.3 and Alstom Grid MiCOM S1 Studio.
4
What type of issue is CAM-2013-2786?
CVE-2013-2786 is a local privilege escalation vulnerability caused by weak file permissions.
5
Can I exploit CVE-2013-2786 remotely?
No, CVE-2013-2786 requires local access to exploit the privilege escalation.