SALTO ProAccess Space
An authenticated operator in SALTO ProAccess Space can escalate privileges and gain unauthorized access to spaces outside their assigned partition. The vulnerability exists because the access control system fails to properly enforce partition boundaries when an authenticated user attempts to escalate their privilege level. Exploitation requires valid operator credentials and depends on the partition (tenancy) feature being active. Installations using a single partition without partitioning enabled are not affected.
- Valid authenticated operator credentials for ProAccess Space
- Partition feature must be enabled on the installation
- Access to the ProAccess Space management interface or API
Patching may require device reboot — plan for process interruption
/api/v1/advisories/358cefe0-0287-476a-a668-a1c51af7e5ccGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.