Back

HIGH

Measuresoft ScadaPro Server Improper Access Control

Published Sep 23, 2022

Description

The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modify the service binary path and start malicious commands with SYSTEM privileges.

Affected products

Remediation

Vendor solution

Measuresoft recommends the following steps to remove full access to the ORCHESTRATOR service: 1. Open a command-line window (CMD) with 'run as administrator' 2. Use the following command to make the permission change to the ORCHESTRATOR service: sc sdset ORCHESTRATOR D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU) 3. As a low-level user, attempt to shut down the ORCHESTRATOR service: sc stop ORCHESTRATOR. User will be denied. It will no longer be possible to edit the configuration of the service by a low-level user.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Sep 23, 2022
Updated Apr 16, 2025
Reserved Sep 21, 2022
CISA Vulnrichment
Updated Apr 16, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a