

William Knowles of Applied Risk reported these vulnerabilities to CISA.

3.2.2 INCORRECT PERMISSION ASSIGNMENT FOR CRITICAL RESOURCE CWE-732

This may allow privilege escalation.ĬVE-2019-18243 has been assigned to this vulnerability. The affected product allows a local authenticated user to modify system-wide iFIX configurations through the registry. TECHNICAL DETAILS 3.1 AFFECTED PRODUCTSģ.2 VULNERABILITY OVERVIEW 3.2.1 INCORRECT PERMISSION ASSIGNMENT FOR CRITICAL RESOURCE CWE-732 Successful exploitation of these vulnerabilities could allow an attacker to escalate their privileges.
