Vulnerability Description
The FACSChorus software does not properly assign data access privileges for operating system user accounts. A non-administrative OS account can modify information stored in the local application data folders.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bd | Facschorus | 5.0 |
| Hp | Hp Z2 Tower G9 | - |
| Hp | Hp Z2 Tower G5 | - |
Related Weaknesses (CWE)
References
- https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-facschorus-softwareVendor Advisory
- https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-facschorus-softwareVendor Advisory
FAQ
What is CVE-2023-29066?
CVE-2023-29066 is a vulnerability with a CVSS score of 3.2 (LOW). The FACSChorus software does not properly assign data access privileges for operating system user accounts. A non-administrative OS account can modify information stored in the local application data ...
How severe is CVE-2023-29066?
CVE-2023-29066 has been rated LOW with a CVSS base score of 3.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-29066?
Check the references section above for vendor advisories and patch information. Affected products include: Bd Facschorus, Hp Hp Z2 Tower G9, Hp Hp Z2 Tower G5.