Vulnerability Details CVE-2021-22682
Cscape (All versions prior to 9.90 SP4) is configured by default to be installed for all users, which allows full permissions, including read/write access. This may allow unprivileged users to modify the binaries and configuration files and lead to local privilege escalation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 7.7%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 4.6
Products affected by CVE-2021-22682
-
cpe:2.3:a:hornerautomation:cscape:9.70
-
cpe:2.3:a:hornerautomation:cscape:9.80
-
cpe:2.3:a:hornerautomation:cscape:9.80.75.3
-
cpe:2.3:a:hornerautomation:cscape:9.90