Incorrect permissions are set to default on the ‘Project Management’ page of WebAccess/SCADA portal of WebAccess/SCADA Versions 9.0.1 and prior, which may allow a low-privileged user to update an administrator’s password and login as an administrator to escalate privileges on the system.
References
Link | Resource |
---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-21-103-02 | Third Party Advisory US Government Resource |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: icscert
Published: 2021-04-26T18:59:08
Updated: 2021-04-26T18:59:08
Reserved: 2021-01-05T00:00:00
Link: CVE-2021-22669
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-04-26T19:15:08.417
Modified: 2021-05-07T18:29:08.803
Link: CVE-2021-22669
JSON object: View
Redhat Information
No data.
CWE