CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential account compromise when an attacker with privileged local access reads improperly protected system files.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 4
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Schneider-Electric Easylogic_T150_Firmware
cpe:2.3:o:schneider-electric:easylogic_t150_firmware:*:*:*:*:*:*:*:*
|
— |
11.06.32
|
|
Schneider-Electric Easylogic_T150
cpe:2.3:h:schneider-electric:easylogic_t150:-:*:*:*:*:*:*:*
|
— | — |
|
Schneider-Electric Saitel_Dp_Firmware
cpe:2.3:o:schneider-electric:saitel_dp_firmware:*:*:*:*:*:*:*:*
|
— |
11.06.38
|
|
Schneider-Electric Saitel_Dp
cpe:2.3:h:schneider-electric:saitel_dp:-:*:*:*:*:*:*:*
|
— | — |