Vulnerability Description
Alstom Grid MiCOM S1 Agile before 1.0.3 and Alstom Grid MiCOM S1 Studio use weak permissions for the MiCOM S1 %PROGRAMFILES% directory, which allows local users to gain privileges via a Trojan horse executable file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alstom | Micom S1 Agile | <= 1.0.2 |
| Alstom | Micom S1 Studio | - |
Related Weaknesses (CWE)
References
- http://ics-cert.us-cert.gov/advisories/ICSA-13-184-01US Government Resource
- http://ics-cert.us-cert.gov/advisories/ICSA-13-184-01US Government Resource
FAQ
What is CVE-2013-2786?
CVE-2013-2786 is a vulnerability with a CVSS score of 6.6 (MEDIUM). Alstom Grid MiCOM S1 Agile before 1.0.3 and Alstom Grid MiCOM S1 Studio use weak permissions for the MiCOM S1 %PROGRAMFILES% directory, which allows local users to gain privileges via a Trojan horse e...
How severe is CVE-2013-2786?
CVE-2013-2786 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-2786?
Check the references section above for vendor advisories and patch information. Affected products include: Alstom Micom S1 Agile, Alstom Micom S1 Studio.