CVE-2018-10604 Vulnerability Details

  /     /     /  

CVE-2018-10604 Metadata Quick Info

CVE Published: 24/07/2018 | CVE Updated: 16/09/2024 | CVE Year: 2018
Source: icscert | Vendor: Schweitzer Engineering Laboratories, Inc. | Product: Compass
Status : PUBLISHED

CVE-2018-10604 Description

SEL Compass version 3.0.5.1 and prior allows all users full access to the SEL Compass directory, which may allow modification or overwriting of files within the Compass installation folder, resulting in escalation of privilege and/or malicious code execution.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-276
CWE Name: INCORRECT DEFAULT PERMISSIONS CWE-276
Source: Schweitzer Engineering Laboratories, Inc.

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).