PT-2019-18156 · Ge+1 · Ge Communicator+1
Reid Wightman
·
Publicado
2019-05-09
·
Atualizado
2020-10-16
·
CVE-2019-6544
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GE Communicator versions prior to 4.0.517
Description
The issue allows an unprivileged user to perform certain administrative actions, potentially enabling the execution of scheduled scripts with system administrator privileges. This is due to a service running with system privileges. However, the service is inaccessible to attackers if Windows default firewall settings are used.
Recommendations
For GE Communicator versions prior to 4.0.517, update to version 4.0.517 or later to resolve the issue. As a temporary workaround, consider using Windows default firewall settings to restrict access to the vulnerable service.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ge Communicator
Windows