CVE-2018-10604

HIGH

SEL Compass <3.0.5.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

SEL Compass version 3.0.5.1 and prior allows all users full access to the SEL Compass directory, which may allow modification or overwriting of files within the Compass installation folder, resulting in escalation of privilege and/or malicious code execution.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-18-191-02

Scores

CVSS v3 8.8
EPSS 0.0164
EPSS Percentile 73.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-276
Status published
Products (1)
selinc/sel_compass < 3.0.5.1
Published Jul 24, 2018
Tracked Since Feb 18, 2026