PT-2019-9111 · Expressvpn · Expressvpn
Published
2019-01-02
·
Updated
2019-01-30
·
CVE-2018-15490
CVSS v2.0
6.6
Medium
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
ExpressVPN (affected versions not specified)
Description
An issue was discovered in ExpressVPN on Windows, where the Xvpnd.exe process listens on TCP port 2015, using a JSON-RPC protocol over HTTP for communication with the client side of the application. The JSON-RPC
XVPN.GetPreference and XVPN.SetPreference methods are vulnerable to path traversal, allowing reading and writing files on the file system on behalf of the service.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Expressvpn