First published: Mon Aug 31 2020(Updated: )
Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification for versions) which could cause local privilege escalation when the Modbus Serial Driver service is invoked. The driver does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Modbus Driver Suite | <14.15.0.0 | |
Schneider-electric Modbus Serial Driver | <2.20_ie_30 | |
Schneider-electric Modbus Serial Driver | <3.20_ie_30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.