PT-2019-15289 · Advantech · Advantech Wise-Paas/Rmm

Trendytofu

·

Published

2019-10-31

·

Updated

2021-05-13

·

CVE-2019-18227

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Advantech WISE-PaaS/RMM versions 3.3.29 and prior
Description The issue concerns XML External Entity (XXE) vulnerabilities that may allow the disclosure of sensitive data. Multiple components within Advantech WISE-PaaS/RMM are affected, including WechatSignin, RecoveryMgmt, and AccountMgmt, where various XML External Entity Processing Information Disclosure Vulnerabilities exist. These vulnerabilities can be exploited through different endpoints and parameters, potentially leading to the disclosure of sensitive information.
Recommendations For Advantech WISE-PaaS/RMM versions 3.3.29 and prior, update to a version later than 3.3.29 to resolve the issue. As a temporary workaround, consider restricting access to the affected components, such as WechatSignin, RecoveryMgmt, and AccountMgmt, until a patch is available. Avoid using the vulnerable XML External Entity processing functionality in the affected components until the issue is resolved.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-18227
ZDI-19-936
ZDI-19-939
ZDI-19-942
ZDI-19-943
ZDI-19-944
ZDI-19-945
ZDI-19-946
ZDI-19-947
ZDI-19-953
ZDI-19-954
ZDI-19-959

Affected Products

Advantech Wise-Paas/Rmm