PT-2023-28688 · Dell · Powerprotect Agent For File System
CVE-2023-43081
·
Publicado
2023-11-22
·
Atualizado
2023-11-27
CVSS v3.1
4.0
Média
| Vetor | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PowerProtect Agent for File System versions 19.14 and prior
Description
The issue is related to incorrect default permissions in the ddfscon component, allowing a low-privileged local attacker to potentially overwrite log files.
Recommendations
For versions 19.14 and prior, consider restricting access to the ddfscon component to prevent potential exploitation until a fix is available. As a temporary workaround, monitor log files closely for any unauthorized modifications.
Correção
Incorrect Default Permissions
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Powerprotect Agent For File System