First published: Fri Jan 28 2022(Updated: )
A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech DeviceOn/iEdge | =1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-40389 is high.
Advantech DeviceOn/iEdge Server version 1.0.2 is affected by CVE-2021-40389.
CVE-2021-40389 is a privilege escalation vulnerability that allows an attacker to replace a specific file in the system to gain NT SYSTEM privileges.
To fix CVE-2021-40389, it is recommended to update to a patched version of Advantech DeviceOn/iEdge Server.
More information about CVE-2021-40389 can be found at https://talosintelligence.com/vulnerability_reports/TALOS-2021-1400.