PT-2019-14778 · Integard · Integard Pro
Publicado
2019-09-23
·
Atualizado
2019-12-06
·
CVE-2019-16702
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Integard Pro version 2.2.0.9026
Description
The issue allows remote attackers to execute arbitrary code via a buffer overflow. This is achieved by providing a long
NoJs parameter to the "/LoginAdmin" API endpoint.Recommendations
For Integard Pro version 2.2.0.9026, consider restricting access to the "/LoginAdmin" API endpoint until a patch is available. As a temporary workaround, avoid using long values for the
NoJs parameter to minimize the risk of exploitation.Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Integard Pro