VulnerabilityModified
CVE-2018-16207
PowerAct Pro Master Agent for Windows Version 5.13 and earlier allows authenticated attackers to bypass access restriction to alter or edit unauthorized files via unspecified vectors.
MEDIUM 6.5EPSS 1.31%
Does this matter?
Lower severity and a low EPSS score (1.31%). Track it; it rarely justifies an emergency change on its own.
Description
PowerAct Pro Master Agent for Windows Version 5.13 and earlier allows authenticated attackers to bypass access restriction to alter or edit unauthorized files via unspecified vectors.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.31% probability · 69th percentile
- CISA KEV
- Not listed
- Affected
- omron/poweract pro master agent
- Source
- vultures@jpcert.or.jp
References
- https://jvn.jp/en/jp/JVN63981842/index.htmlThird Party Advisory
- https://www.oss.omron.co.jp/ups/info/topics/190326.htmlVendor Advisory
- https://www.oss.omron.co.jp/ups/support/download/soft/poweractpro/master/poweractpro_master_windows.htmlProduct
- https://jvn.jp/en/jp/JVN63981842/index.htmlThird Party Advisory
- https://www.oss.omron.co.jp/ups/info/topics/190326.htmlVendor Advisory
- https://www.oss.omron.co.jp/ups/support/download/soft/poweractpro/master/poweractpro_master_windows.htmlProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.