First published: Tue Feb 20 2024(Updated: )
Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access.
Credit: security@ni.com
Affected Software | Affected Version | How to fix |
---|---|---|
Emerson Data Record Ad | <=2.0.1 | |
Emerson Flexlogger | <=2022_q3 | |
Emerson G Web Development Software | <=2022_q3 | |
LabVIEW NXG | =5.1 | |
LabVIEW NXG | =5.1 | |
LabVIEW NXG | =5.1 | |
Emerson Specification Compliance Manager | <=2023_q4 | |
Emerson STS Software Bundle | <=1.2 | |
Emerson STS Software Bundle | <=21.0 | |
Emerson Systemlink Server | <2024_q1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1155 is classified as a high severity vulnerability due to the potential for privilege escalation.
To fix CVE-2024-1155, ensure that the installation directories for shared SystemLink Elixir-based services have the correct permissions set.
CVE-2024-1155 affects users of specific Emerson software including Data Record Ad, Flexlogger, and LabVIEW NXG versions up to specified limits.
CVE-2024-1155 is an incorrect permissions vulnerability that could allow an authenticated user to escalate privileges.
No, CVE-2024-1155 requires local access to exploit the incorrect permissions.