CVE-2017-7968: High severity aveva indusoft web studio vulnerability
An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. Upon installation, Wonderware InduSoft Web Studio creates a new directory and two files, which are placed in the system's path and can be manipulated by non-administrators. This could allow an authenticated user to escalate his or her privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7968?
CVE-2017-7968 has a medium severity rating due to its Incorrect Default Permissions issue.
How do I fix CVE-2017-7968?
To fix CVE-2017-7968, ensure that the default permissions for the directories and files created during installation are properly configured to restrict access.
Which versions of Wonderware InduSoft Web Studio are affected by CVE-2017-7968?
CVE-2017-7968 affects Schneider Electric Wonderware InduSoft Web Studio version 8.0 Patch 3 and earlier versions.
What kind of risk does CVE-2017-7968 pose?
CVE-2017-7968 poses a risk of unauthorized access and potential manipulation of system files by non-administrative users.
Is there a patch available for CVE-2017-7968?
As of the identification of CVE-2017-7968, users should check Schneider Electric's channels for any patches or security updates related to this vulnerability.