PT-2019-18094 · Es · Es File Explorer File Manager
Fs0C131Y
·
Publicado
2019-01-16
·
Atualizado
2023-02-01
·
CVE-2019-6447
CVSS v3.1
8.1
Alta
| Vetor | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ES File Explorer File Manager versions through 4.1.9.7.4
Description
The issue allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated application/json data over HTTP.
Recommendations
For ES File Explorer File Manager versions through 4.1.9.7.4, as a temporary workaround, consider disabling the application's ability to listen on TCP port 59777 until a patch is available. Restrict access to the local Wi-Fi network to minimize the risk of exploitation. Avoid using the ES File Explorer File Manager application until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Es File Explorer File Manager