PT-2019-13414 · Advantech · Wise-Paas/Rmm
Rgod
·
Published
2019-10-31
·
Updated
2021-05-13
·
CVE-2019-13551
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Advantech WISE-PaaS/RMM versions 3.3.29 and prior
Description
The issue is caused by a lack of proper validation of a user-supplied path prior to use in file operations, leading to path traversal vulnerabilities. An attacker can leverage these vulnerabilities to remotely execute code while posing as an administrator. The vulnerabilities are related to directory traversal in various components, including upload2eMap, upload ota, RMSWatchDog distributer, and UpgradeMgmt.
Recommendations
For Advantech WISE-PaaS/RMM versions 3.3.29 and prior, consider disabling the affected directory traversal functionalities in upload2eMap, upload ota, RMSWatchDog distributer, and UpgradeMgmt until a patch is available. Restrict access to these components to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wise-Paas/Rmm