CVE-2023-28870
MEDIUM
6,5
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: high
Availability: none
Description
AI Translation Available
Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to configuration files from low-privileged user accounts.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0004
Percentile
0,1th
Updated
EPSS Score Trend (Last 90 Days)
276
Incorrect Default Permissions
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Potential Impacts:
Read Application Data
Modify Application Data
Applicable Platforms
Technologies:
Not Technology-Specific, ICS/OT
Application
Secure Enterprise Client by Ncp-E
Version Range Affected
To
12.22
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:ncp-e:secure_enterprise_client:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://herolab.usd.de/en/security-advisories/usd-2022-0004/
https://herolab.usd.de/en/security-advisories/usd-2022-0004/