PT-2023-12716 · Ip Label · Ip-Label Newtest
CVE-2022-23334
·
Publicado
2023-01-30
·
Atualizado
2023-02-06
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ip-label Newtest versions prior to 8.5R0
Description
The Robot application in Ip-label Newtest was discovered to use weak signature checks on executed binaries. This allows attackers to have write access and escalate privileges via replacing NEWTESTREMOTEMANAGER.EXE.
Recommendations
For versions prior to 8.5R0, update to version 8.5R0 or later to resolve the issue. As a temporary workaround, consider restricting access to the NEWTESTREMOTEMANAGER.EXE file to minimize the risk of exploitation.
Exploit
Correção
Improper Verification of Cryptographic Signature
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ip-Label Newtest