CVE-2022-41976: Critical severity scada-lts vulnerability
An privilege escalation issue was discovered in Scada-LTS 2.7.1.1 build 2948559113 allows remote attackers, authenticated in the application as a low-privileged user to change role (e.g., to administrator) by updating their user profile.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-41976?
CVE-2022-41976 is a privilege escalation vulnerability discovered in Scada-LTS 2.7.1.1 build 2948559113, allowing remote attackers to change their role to administrator by updating their user profile.
How severe is CVE-2022-41976?
CVE-2022-41976 has a severity rating of critical with a CVSS score of 8.8.
What software versions are affected by CVE-2022-41976?
CVE-2022-41976 affects Scada-LTS versions up to and excluding 2.7.3.
How can I fix CVE-2022-41976?
To fix CVE-2022-41976, update Scada-LTS to version 2.7.3 or later.
Where can I find more information about CVE-2022-41976?
More information about CVE-2022-41976 can be found on the Scada-LTS website, the Scada-LTS GitHub releases page, and a blog post by M3n0sD0n4ld.