"value":"In Rapid Software LLC's Rapid SCADA versions prior to\u00a0Version 5.8.4,\u00a0an authorized user can write directly to the Scada directory. This may allow privilege escalation.\n"
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-732 Incorrect Permission Assignment for Critical Resource",
"value":"\nRapid Software did not respond to CISA's attempts at coordination. Users\n of Rapid SCADA are encouraged to contact Rapid Software and keep their \nsystems up to date.\n\n<br>"
}
],
"value":"Rapid Software did not respond to CISA's attempts at coordination. Users\n of Rapid SCADA are encouraged to contact Rapid Software and keep their \nsystems up to date.\n\n\n"
}
],
"credits":[
{
"lang":"en",
"value":"Noam Moshe of Claroty Research reported these vulnerabilities to CISA."