PT-2019-19766 · Safenet · Esafenet Cdg

Publicado

2019-03-08

·

Atualizado

2020-08-24

·

CVE-2019-9632

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ESAFENET CDG versions V3 and V5
Description The issue concerns an arbitrary file download vulnerability. It can be exploited via the fileName parameter in the "download.jsp" endpoint, specifically when the InstallationPack parameter is mishandled in a "/CDGServer3/ClientAjax" request.
Recommendations For versions V3 and V5, consider restricting access to the "download.jsp" endpoint until a fix is available. As a temporary workaround, avoid using the fileName parameter in the "/CDGServer3/ClientAjax" request to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2019-9632

Produtos afetados

Esafenet Cdg