CVE-2024-31201

A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service. Such misconfiguration could be abused in scenarios where incorrect permissions were assigned to the C:\ path to attempt a privilege escalation on the local machine.

Credits

Diego Zaffaroni of Nozomi Networks found this bug during a security research activity.

References