AccuPOS
Incorrect Permission Assignment for Critical Resource
CVE ID
Vendor
AccuPOS, Inc.
Product
AccuPOS
Product Version
Version, 2017.8
Vulnerability Details
The AccuPOS Point Of Sale Application is installed with the insecure “Authenticated Users: Modify” permission for files within the installation path. This may allow local attackers to compromise the integrity of critical resource and executable files.
Vendor Response
AccuPOS has not remediated the vulnerability.
Disclosure Timeline
-
Disclosed to Vendor
-
Follow up via Email
-
No response from vendor
-
Publicly disclosed at BSides ATL