PT-2019-14778 · Integard · Integard Pro

Published

2019-09-23

·

Updated

2019-12-06

·

CVE-2019-16702

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Integard Pro version 2.2.0.9026
Description The issue allows remote attackers to execute arbitrary code via a buffer overflow. This is achieved by providing a long NoJs parameter to the "/LoginAdmin" API endpoint.
Recommendations For Integard Pro version 2.2.0.9026, consider restricting access to the "/LoginAdmin" API endpoint until a patch is available. As a temporary workaround, avoid using long values for the NoJs parameter to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16702

Affected Products

Integard Pro