PT-2023-23130 · Tsplus · Tsplus Remote Access

·

CVE-2023-31067

·

Published

2023-09-11

·

Updated

2023-10-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TSplus Remote Access versions through 16.0.2.14
Description An issue was discovered in TSplus Remote Access where some directories under %PROGRAMFILES(X86)%TSplusClientswww have Full Control permissions for Everyone.
Recommendations For versions through 16.0.2.14, restrict access to the directories under %PROGRAMFILES(X86)%TSplusClientswww to minimize the risk of exploitation by removing Full Control permissions for the Everyone group.

Exploit

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-31067

Affected Products

Tsplus Remote Access