Skip to main content

Incorrect Default Permissions


Severity Medium
Score 5.5/10


An issue was discovered in SALTO ProAccess SPACE The product's webserver runs as a Windows service with local SYSTEM permissions by default. This is against the principle of least privilege. An attacker who is able to exploit CVE-2019-19458 or CVE-2019-19459 is basically able to write to every single path on the file system, because the webserver is running with the highest privileges available.

  • LOW
  • HIGH
  • NONE
  • LOW
  • NONE
  • NONE

CWE-276 - Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.


Advisory Timeline

  • Published