PT-2020-19811 · Raon · Raonwiz
Published
2020-07-10
·
Updated
2021-07-21
·
CVE-2020-7814
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RAONWIZ versions prior to 2018.0.2.51
Description
The issue is related to a lack of validation to file extensions, which could allow remote files to be downloaded and executed. This can be used for remote-code-execution attacks by hackers. The vulnerability is in the RAON KUpload component of RAONWIZ.
Recommendations
For versions prior to 2018.0.2.51, update to version 2018.0.2.51 or later to resolve the issue. As a temporary workaround, consider restricting access to the RAON KUpload component to minimize the risk of exploitation. Avoid using the vulnerable file download and execution functionality in RAONWIZ until the issue is resolved.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Raonwiz