PT-2018-9731 · Digital Guardian · Digital Guardian Management Console

Published

2018-04-20

·

Updated

2018-05-22

·

CVE-2018-10173

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Digital Guardian Management Console version 7.1.2.0015
Description: The issue allows authenticated remote code execution due to Arbitrary File Upload functionality.
Recommendations: For Digital Guardian Management Console version 7.1.2.0015, consider restricting access to the Arbitrary File Upload functionality as a temporary workaround until a patch is available.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10173

Affected Products

Digital Guardian Management Console