Foxboro Sys Faces Local Denial-of-Service and Privilege Escalation Vulnerability
CVE-2024-5681
7.8HIGH
Summary
An improper input validation vulnerability in the Foxboro.sys driver can enable a local user with malicious intent to craft a script or program that exploits the vulnerability through an IOCTL call. This exploitation may lead to local denial-of-service, privilege escalation, and even potential kernel execution. The flaw poses a risk to users with local access, emphasizing the need for immediate action and remediation. Users are advised to review Schneider Electric's security notice for guidelines on mitigating potential impacts.
Affected Version(s)
EcoStruxure Foxboro DCS Core Control Services Versions 9.8 and prior
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database