Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2023-38641

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.10). The affected application's database service is executed as `NT AUTHORITY\SYSTEM`. This could allow a local attacker to execute operating system commands with elevated privileges.
Attacker Value
Unknown

CVE-2022-39062

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.10). Affected applications do not properly set permissions for product folders. This could allow an authenticated attacker with low privileges to replace DLLs and conduct a privilege escalation.
Attacker Value
Unknown

CVE-2021-45106

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
A vulnerability has been identified in SICAM TOOLBOX II (All versions). Affected applications use a circumventable access control within a database service. This could allow an attacker to access the database.