vendor:
TSplus
by:
Carlo Di Dato for Deloitte Risk Advisory Italia
9.8
CVSS
CRITICAL
Insecure Files and Folders Permissions
732
CWE
Product Name: TSplus
Affected Version From: Up to 16.0.2.14
Affected Version To: Up to 16.0.2.14
Patch Exists: NO
Related CWE: CVE-2023-31067
CPE: a:tsplus:tsplus:16.0.2.14
Platforms Tested: Windows
2023
TSplus 16.0.2.14 – Remote Access Insecure Files and Folders Permissions
TSplus Remote Access (v. 16.0.2.14) has insecure file and folder permissions, which can allow a malicious user to manipulate file content or change legitimate files to compromise the system or gain elevated privileges.
Mitigation:
The vendor should update the permissions of the insecure files and folders to restrict access to authorized users only. Users are advised to update to the latest version of TSplus to mitigate this vulnerability.