A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver installed by the runtime software of EcoStruxureª Operator Terminal Expert.
2020-11-19T22:15:14.113
2024-11-21T05:37:21.100
Modified
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | schneider-electric | operator_terminal_expert_runtime | < 3.1 | Yes |
| Application | schneider-electric | operator_terminal_expert_runtime | 3.1 | Yes |
| Application | schneider-electric | operator_terminal_expert_runtime | 3.1 | Yes |