PT-2018-17450 · Kaspersky · Kaspersky Secure Mail Gateway
Publicado
2018-02-01
·
Atualizado
2018-02-23
·
CVE-2018-6289
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kaspersky Secure Mail Gateway version 1.1
Description
The issue is related to configuration file injection, which can lead to code execution as root.
Recommendations
For Kaspersky Secure Mail Gateway version 1.1, update to a version that fixes the configuration file injection issue to prevent code execution as root.
Exploit
Correção
Special Elements Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Kaspersky Secure Mail Gateway