PT-2019-13414 · Advantech · Wise-Paas/Rmm
Rgod
·
Publicado
2019-10-31
·
Atualizado
2021-05-13
·
CVE-2019-13551
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Advantech WISE-PaaS/RMM versions 3.3.29 and prior
Description
The issue is caused by a lack of proper validation of a user-supplied path prior to use in file operations, leading to path traversal vulnerabilities. An attacker can leverage these vulnerabilities to remotely execute code while posing as an administrator. The vulnerabilities are related to directory traversal in various components, including upload2eMap, upload ota, RMSWatchDog distributer, and UpgradeMgmt.
Recommendations
For Advantech WISE-PaaS/RMM versions 3.3.29 and prior, consider disabling the affected directory traversal functionalities in upload2eMap, upload ota, RMSWatchDog distributer, and UpgradeMgmt until a patch is available. Restrict access to these components to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wise-Paas/Rmm