First published: Fri May 19 2017(Updated: )
An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. Upon installation, Wonderware InduSoft Web Studio creates a new directory and two files, which are placed in the system's path and can be manipulated by non-administrators. This could allow an authenticated user to escalate his or her privileges.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
AVEVA InduSoft Web Studio | <=8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7968 has a medium severity rating due to its Incorrect Default Permissions issue.
To fix CVE-2017-7968, ensure that the default permissions for the directories and files created during installation are properly configured to restrict access.
CVE-2017-7968 affects Schneider Electric Wonderware InduSoft Web Studio version 8.0 Patch 3 and earlier versions.
CVE-2017-7968 poses a risk of unauthorized access and potential manipulation of system files by non-administrative users.
As of the identification of CVE-2017-7968, users should check Schneider Electric's channels for any patches or security updates related to this vulnerability.