A local unprivileged attacker may escalate to administrator privileges in Honeywell SoftMaster version 4.51, due to insecure permission assignment.CreditsNoam Moshe of Claroty Research reported these vulnerabilities to Honeywell.Referenceshttps://www.cisa.gov/uscert/ics/advisories/icsa-22-256-02https://www.security.honeywell.com/-/media/Security/Resources/PDF/Product-Warranty/Security_Notification_SN_2019-09-13-02_V4-pdf.pdf