In IXP EasyInstall 6.2.13723, there is Directory Traversal on TCP port 8000 via the Engine Service by an unauthenticated attacker, who can access the server's filesystem with the access rights of NT AUTHORITY\SYSTEM.
References
Link | Resource |
---|---|
https://improsec.com/tech-blog/multiple-vulnerabilities-in-easyinstall-rmm-and-deployment-software | Exploit Third Party Advisory |
Configurations
Information
Published : 2020-01-23 13:15
Updated : 2020-01-29 12:50
NVD link : CVE-2019-19893
Mitre link : CVE-2019-19893
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
ixpdata
- easyinstall