PT-2020-19826 · Raon · Raonwiz
Published
2020-09-02
·
Updated
2020-09-11
·
CVE-2020-7830
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RAONWIZ versions 2018.0.2.50 and earlier
Description
The issue is related to a lack of validation that could allow remote files to be downloaded. Specifically, vulnerabilities in the Kupload agent enable files to be downloaded to arbitrary paths due to insufficient verification of extensions and download paths.
Recommendations
For RAONWIZ versions 2018.0.2.50 and earlier, consider restricting the use of the Kupload agent until a fix is available to prevent arbitrary file downloads. As a temporary workaround, restrict access to the download functionality to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Raonwiz