Weak ACL in Geist WatchDog Console 3.2.2 allows unauthorized modification of configuration data

Weak ACL in Geist WatchDog Console 3.2.2 allows unauthorized modification of configuration data

CVE-2018-10079 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Geist WatchDog Console 3.2.2 uses a weak ACL for the C:\ProgramData\WatchDog Console directory, which allows local users to modify configuration data by updating (1) config.xml or (2) servers.xml.

Learn more about our Cis Benchmark Audit For Server Software.