PT-2020-10313 · Selesta · Selesta Visual Access Manager

Published

2020-02-26

·

Updated

2020-02-27

·

CVE-2019-19994

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Selesta Visual Access Manager (VAM) versions 4.15.0 through 4.29
Description An issue in Selesta Visual Access Manager allows blind Command Injection, enabling an attacker without authentication to execute arbitrary operating system commands. This is achieved by injecting a vulnerable parameter in the PHP Web page /common/vam monitor sap.php.
Recommendations For versions 4.15.0 through 4.29, consider restricting access to the /common/vam monitor sap.php endpoint until a fix is available, and avoid using the vulnerable parameter to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19994

Affected Products

Selesta Visual Access Manager