PT-2020-13855 · Ozeki · Ozeki Ng Sms Gateway

Drunkenshells

·

Published

2020-09-22

·

Updated

2020-09-26

·

CVE-2020-14031

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ozeki NG SMS Gateway versions through 4.17.6
Description An issue was discovered in the outbox functionality of the TXT File module, allowing it to delete most files in a folder. Since the product typically runs as NT AUTHORITYSYSTEM, the only files that will not be deleted are those currently being run by the system and/or files with special security attributes.
Recommendations For Ozeki NG SMS Gateway versions through 4.17.6, consider restricting access to the outbox functionality of the TXT File module to prevent unauthorized file deletion until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-14031

Affected Products

Ozeki Ng Sms Gateway