CVE-2018-1168
Summary
| CVE | CVE-2018-1168 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-21 14:29:00 UTC |
| Updated | 2023-05-16 21:04:00 UTC |
| Description | This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB MicroSCADA 9.3 with FP 1-2-3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of the access controls for the installed product files. The installation procedure leaves critical files open to manipulation by any authenticated user. An attacker can leverage this vulnerability to escalate privileges to SYSTEM. Was ZDI-CAN-5097. |
Risk And Classification
Problem Types: CWE-732
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Abb | Sys600 | - | All | All | All |
| Hardware | Abb | Sys600 | - | All | All | All |
| Operating System | Abb | Sys600 Firmware | 9.0 | All | All | All |
| Operating System | Abb | Sys600 Firmware | 9.1 | All | All | All |
| Operating System | Abb | Sys600 Firmware | 9.1.5 | All | All | All |
| Operating System | Abb | Sys600 Firmware | 9.2 | All | All | All |
| Operating System | Abb | Sys600 Firmware | 9.4 | All | All | All |
| Operating System | Abb | Sys600 Firmware | 9.0 | All | All | All |
| Operating System | Abb | Sys600 Firmware | 9.1 | All | All | All |
| Operating System | Abb | Sys600 Firmware | 9.1.5 | All | All | All |
| Operating System | Abb | Sys600 Firmware | 9.2 | All | All | All |
| Operating System | Abb | Sys600 Firmware | 9.4 | All | All | All |
| Hardware | Hitachienergy | Sys600 | - | All | All | All |
| Operating System | Hitachienergy | Sys600 Firmware | 9.0 | All | All | All |
| Operating System | Hitachienergy | Sys600 Firmware | 9.1 | All | All | All |
| Operating System | Hitachienergy | Sys600 Firmware | 9.1.5 | All | All | All |
| Operating System | Hitachienergy | Sys600 Firmware | 9.2 | All | All | All |
| Operating System | Hitachienergy | Sys600 Firmware | 9.4 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ZDI-18-141 | Zero Day Initiative | MISC | zerodayinitiative.com | Third Party Advisory, VDB Entry |
| library.e.abb.com/public/7a88a74b12bb492ea138b1f2365d00f6/ABBVU-PGGA-33888_ABB_... | CONFIRM | library.e.abb.com | Mitigation, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.