A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service. Such misconfiguration could be abused in scenarios where incorrect permissions were assigned to the C:\ path to attempt a privilege escalation on the local machine.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-29105 A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service. Such misconfiguration could be abused in scenarios where incorrect permissions were assigned to the C:\ path to attempt a privilege escalation on the local machine.
Fixes

Solution

No official patch available from vendor. Conduct regular and thorough reviews of logs and user accounts on systems running the Thermoscan IP software. This will help identify and address any suspicious activities early, ensuring that any potential security breaches are caught and remediated swiftly.


Workaround

No workaround given by the vendor.

History

Mon, 12 Aug 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Proges
Proges thermoscan Ip
CPEs cpe:2.3:a:proges:thermoscan_ip:20211103:*:*:*:*:*:*:*
Vendors & Products Proges
Proges thermoscan Ip

cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2024-08-01T14:52:47.793Z

Reserved: 2024-03-29T08:32:14.699Z

Link: CVE-2024-31201

cve-icon Vulnrichment

Updated: 2024-08-01T14:52:41.495Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-31T14:15:04.430

Modified: 2024-08-12T18:46:10.823

Link: CVE-2024-31201

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.