PT-2007-5345 · Visionsoft · Visionsoft Audit
Published
2007-08-03
·
Updated
2012-11-06
·
CVE-2007-4149
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Visionsoft Audit version 12.4.0.0
Description
The issue concerns the Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit, where certain commands do not require authentication. Specifically, the
LOG. command allows remote attackers to create or overwrite arbitrary files, potentially leading to code execution by writing to a Startup folder. The SETTINGSFILE command enables remote attackers to overwrite the ini file, reconfigure VSAOD, or cause a denial of service. Additionally, the UNINSTALL command allows remote attackers to cause a denial of service by shutting down the daemon.Recommendations
For Visionsoft Audit version 12.4.0.0, consider implementing authentication for the
LOG., SETTINGSFILE, and UNINSTALL commands to prevent unauthorized access. As a temporary workaround, restrict access to these commands to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Visionsoft Audit