PT-2019-18094 · Es · Es File Explorer File Manager
Fs0C131Y
·
Published
2019-01-16
·
Updated
2023-02-01
·
CVE-2019-6447
CVSS v3.1
8.1
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ES File Explorer File Manager versions through 4.1.9.7.4
Description
The issue allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated application/json data over HTTP.
Recommendations
For ES File Explorer File Manager versions through 4.1.9.7.4, as a temporary workaround, consider disabling the application's ability to listen on TCP port 59777 until a patch is available. Restrict access to the local Wi-Fi network to minimize the risk of exploitation. Avoid using the ES File Explorer File Manager application until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Es File Explorer File Manager