PT-2019-7150 · Honeywell · Experion Pks

Publicado

2019-04-08

·

Atualizado

2019-10-09

·

CVE-2014-9186

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Honeywell Experion PKS versions prior to R400.6 Honeywell Experion PKS versions prior to R410.6 Honeywell Experion PKS versions prior to R430.2
Description A file inclusion issue exists in the confd.exe module, potentially allowing arbitrary file acceptance into the function. This could lead to information disclosure or remote code execution.
Recommendations For versions prior to R400.6, upgrade to version R400.6 or later. For versions prior to R410.6, upgrade to version R410.6 or later. For versions prior to R430.2, upgrade to version R430.2 or later.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-9186

Produtos afetados

Experion Pks