Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Djo

Researcher frommioso
#23758of 53,622
10Total CVSS
Vulnerabilities · 1
PT-2019-12355
10
2019-10-10
Softing · Uagate Si · CVE-2019-11526
**Name of the Vulnerable Software and Affected Versions** Softing uaGate SI version 1.60.01 **Description** An issue was discovered that allows file path injection via a maintenance script executable with sudo privileges. This enables an attacker to write files with superuser privileges in specific locations. **Recommendations** For Softing uaGate SI version 1.60.01, consider restricting access to the maintenance script to prevent exploitation until a fix is available. As a temporary workaround, limit the use of sudo privileges for the script to minimize the risk of file path injection.