Incorrect Default Permissions Vulnerability Affects MELIPC Series MI5122-VW Firmware Versions 05-07
CVE-2024-3904

8.8HIGH

Key Information:

Vendor
CVE Published:
4 July 2024

Summary

An Incorrect Default Permissions vulnerability exists in the Smart Device Communication Gateway preinstalled on MELIPC Series MI5122-VW firmware versions 05 through 07. This vulnerability allows a local attacker to execute arbitrary code by saving a malicious file in a targeted directory. The exploitation of this vulnerability can lead to unauthorized disclosure, modification, destruction, or deletion of sensitive information within the device. Furthermore, it may result in a denial-of-service condition, thereby impacting the operational capability of the product.

Affected Version(s)

MELIPC Series MI5122-VW Firmware versions "05" to "07"

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.