CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
2024-07-11T09:15:04.360
2024-11-21T09:48:08.953
Modified
CVSSv3.1: 7.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | schneider-electric | ecostruxure_foxboro_dcs_control_core_services | ≤ 9.8 | Yes |