CVE-2024-23847

MEDIUM

Yokogawa Unifier - Incorrect Default Permissions Code Execution as LocalSystem

Title source: manual
STIX 2.1

Description

Incorrect default permissions issue exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be altered or deleted.

Scores

CVSS v3 5.9
EPSS 0.0017
EPSS Percentile 6.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-276
Status published
Products (5)
Yokogawa Rental & Lease Corporation/Unifier Version.5.0 or later but prior to v5.10.6
Yokogawa Rental & Lease Corporation/Unifier and the patch "20240527" not applied
Yokogawa Rental & Lease Corporation/Unifier Cast Version.5.0 or later but prior to v5.10.6
Yokogawa Rental & Lease Corporation/Unifier Cast Version.6.0 or later but prior to v6.5.0
Yokogawa Rental & Lease Corporation/Unifier Cast and the patch "20240527" not applied
Published May 31, 2024
Tracked Since Feb 18, 2026