Impact
Fortra File Integrity Monitoring (FIM) prior to version 9.4.0 can incorrectly assign or elevate effective permissions to users created or modified by the tetool import command while FIM is running. The flaw is an insecure permission management error that may give attackers higher privileges than intended. The upgrade fix resolves the issue.
Affected Systems
Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions earlier than 9.4.0 are impacted. No further version granularity is noted in the advisory.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is internal, requiring an attacker to run the tetool import while FIM is operational. An attacker with the ability to execute tetool could leverage the flaw to grant themselves unauthorized permissions, but the exploit requires pre‑existing privileges to perform the import.
OpenCVE Enrichment