PT-2019-15845 · Saltosystem · Proaccess Space

Werner Schober

·

Published

2019-12-03

·

Updated

2019-12-13

·

CVE-2019-19460

CVSS v2.0

6.6

Medium

VectorAV:L/AC:L/Au:N/C:N/I:C/A:C
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local SYSTEM permissions by default. This is against the principle of least privilege. An attacker who is able to exploit CVE-2019-19458 or CVE-2019-19459 is basically able to write to every single path on the file system, because the webserver is running with the highest privileges available.

Exploit

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19460

Affected Products

Proaccess Space