PT-2019-15291 · Advantech · Wise-Paas/Rmm

Rgod

·

Published

2019-10-31

·

Updated

2021-05-13

·

CVE-2019-18229

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Advantech WISE-PaaS/RMM versions 3.3.29 and prior
Description The issue is caused by a lack of sanitization of user-supplied input, leading to SQL injection vulnerabilities. This allows an attacker to disclose information. The vulnerabilities are present in various components, including SQLMgmt and fuzzySearch functions in different modules such as DeviceMgmt, RecoveryMgmt, ProtectionMgmt, and PowerMgmt.
Recommendations For Advantech WISE-PaaS/RMM versions 3.3.29 and prior, consider disabling the SQLMgmt and fuzzySearch functions until a patch is available to prevent SQL injection attacks. Restrict access to the affected modules to minimize the risk of exploitation. Avoid using user-supplied input in the updateData, insertData, getTableInfo, delData, CreateTable, and qryData functions within the SQLMgmt component, as well as the fuzzySearch function in the DeviceMgmt, RecoveryMgmt, ProtectionMgmt, and PowerMgmt components, until the issue is resolved.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-18229
ZDI-19-937
ZDI-19-938
ZDI-19-940
ZDI-19-948
ZDI-19-949
ZDI-19-951
ZDI-19-952
ZDI-19-955
ZDI-19-956
ZDI-19-957

Affected Products

Wise-Paas/Rmm