Impact
During installation of BRAIN2 versions before 3.09, the LogPathConfig.exe utility is executed, granting the Windows group Everyone full control over the %ProgramData% folder. This misconfiguration allows any local user to read, write, or delete files under that directory, potentially overriding application data or configuration files for BRAIN2 and other software that rely on the folder. The vulnerability is a direct example of improper privilege assignment (CWE‑276).
Affected Systems
Affected vendors include Bizerba SE & Co. KG, specifically the BRAIN2 product line. All installations running BRAIN2 versions older than 3.09 are vulnerable. The optional Bizerba ScriptService component, which remains in the product delivery until BRAIN2 3.11, can trigger the same permission change even after BRAIN2 is updated to 3.09 or later. A fresh installation of BRAIN2 3.09 or newer that omits ScriptService, or an installation that uses the BRAIN2 Device Control Service instead, does not repeat the insecure permission assignment.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity, while the EPSS score of less than 1% signals a very low probability of exploitation. The vulnerability is not listed in CISA KEV. The attack vector is local: an attacker must be able to run the installer or the Bizerba ScriptService component on the target machine. Once the permissions are set, any local account can alter the contents of %ProgramData%, but no remote or privileged escalation beyond local accounts is supported by the description. Administrators should manually correct existing permissions on %ProgramData% if the flaw persists after upgrading.
OpenCVE Enrichment