ZeroHour

CVE-2024-22078

CVSS 3.1
8.8 high
EPSS
<1%p49
Published
()
Modified
Description

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration script has weak filesystem permissions. This results in write access for all authenticated users and the possibility to escalate from user privileges to administrative privileges.

Vendors
elspec-ltd
Products
g5dfr firmware
Weakness
CWE-280
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.