Insecure Inherited Permissions
CVE-2023-29065
Summary
The FACSChorus software database can be accessed directly with the privileges of the currently logged-in user. A threat actor with physical access could potentially gain credentials, which could be used to alter or destroy data stored in the database.
- LOW
- PHYSICAL
- LOW
- UNCHANGED
- NONE
- LOW
- LOW
- LOW
CWE-277 - Insecure Inherited Permissions
A product defines a set of insecure permissions that are inherited by objects that are created by the program.
References
Advisory Timeline
- Published