PT-2019-13414 · Advantech · Wise-Paas/Rmm

Rgod

·

Published

2019-10-31

·

Updated

2021-05-13

·

CVE-2019-13551

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Advantech WISE-PaaS/RMM versions 3.3.29 and prior
Description The issue is caused by a lack of proper validation of a user-supplied path prior to use in file operations, leading to path traversal vulnerabilities. An attacker can leverage these vulnerabilities to remotely execute code while posing as an administrator. The vulnerabilities are related to directory traversal in various components, including upload2eMap, upload ota, RMSWatchDog distributer, and UpgradeMgmt.
Recommendations For Advantech WISE-PaaS/RMM versions 3.3.29 and prior, consider disabling the affected directory traversal functionalities in upload2eMap, upload ota, RMSWatchDog distributer, and UpgradeMgmt until a patch is available. Restrict access to these components to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-13551
ZDI-19-935
ZDI-19-941
ZDI-19-950
ZDI-19-958

Affected Products

Wise-Paas/Rmm