PT-2018-1148 · Dewesoft · Dewesoft X3 Sp1

Hyp3Rlinx

+1

·

Publicado

2018-02-09

·

Atualizado

2018-04-12

·

CVE-2018-7756

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DEWESoft X3 SP1 (64-bit)
Description The issue is related to the RunExeFile.exe in the installer, which does not require authentication for sessions on TCP port 1999. This allows remote attackers to execute arbitrary code or access internal commands. For example, a RUN command can launch a .EXE file from an arbitrary external URL, or a "SETFIREWALL Off" command can be executed.
Recommendations For DEWESoft X3 SP1 (64-bit), consider restricting access to TCP port 1999 until a patch is available. As a temporary workaround, avoid using the RunExeFile.exe feature to execute external files or commands until the issue is resolved. Restrict access to internal commands to minimize the risk of exploitation.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00585
CVE-2018-7756

Produtos afetados

Dewesoft X3 Sp1