PT-2023-12716 · Ip Label · Ip-Label Newtest

CVE-2022-23334

·

Publicado

2023-01-30

·

Atualizado

2023-02-06

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ip-label Newtest versions prior to 8.5R0
Description The Robot application in Ip-label Newtest was discovered to use weak signature checks on executed binaries. This allows attackers to have write access and escalate privileges via replacing NEWTESTREMOTEMANAGER.EXE.
Recommendations For versions prior to 8.5R0, update to version 8.5R0 or later to resolve the issue. As a temporary workaround, consider restricting access to the NEWTESTREMOTEMANAGER.EXE file to minimize the risk of exploitation.

Exploit

Correção

Improper Verification of Cryptographic Signature

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-23334

Produtos afetados

Ip-Label Newtest