First published: Sat Dec 09 2023(Updated: )
Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to configuration files from low-privileged user accounts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ncp-e Secure Enterprise Client | <12.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28870 has been classified as a medium-severity vulnerability due to insecure file permissions.
To mitigate CVE-2023-28870, ensure that correct permissions are set on configuration files to prevent unauthorized access.
CVE-2023-28870 affects NCP Secure Enterprise Client versions prior to 12.22.
CVE-2023-28870 is classified as an insecure file permissions vulnerability.
Yes, low-privileged user accounts can exploit CVE-2023-28870 to write to configuration files.