AccuPOS

Incorrect Permission Assignment for Critical Resource

Vendor

AccuPOS, Inc.

Product

AccuPOS

Product Version

Version, 2017.8

Vulnerability Details

The AccuPOS Point Of Sale Application is installed with the insecure “Authenticated Users: Modify” permission for files within the installation path. This may allow local attackers to compromise the integrity of critical resource and executable files.

Vendor Response

AccuPOS has not remediated the vulnerability.

Disclosure Timeline

  • Disclosed to Vendor

  • Follow up via Email

  • No response from vendor

  • Publicly disclosed at BSides ATL