PT-2019-18094 · Es · Es File Explorer File Manager

Fs0C131Y

·

Published

2019-01-16

·

Updated

2023-02-01

·

CVE-2019-6447

CVSS v3.1

8.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ES File Explorer File Manager versions through 4.1.9.7.4
Description The issue allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated application/json data over HTTP.
Recommendations For ES File Explorer File Manager versions through 4.1.9.7.4, as a temporary workaround, consider disabling the application's ability to listen on TCP port 59777 until a patch is available. Restrict access to the local Wi-Fi network to minimize the risk of exploitation. Avoid using the ES File Explorer File Manager application until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2019-6447

Affected Products

Es File Explorer File Manager