PT-2020-9218 · Aleos · Aleos

Published

2020-08-21

·

Updated

2022-02-09

·

CVE-2019-11857

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ALEOS versions prior to 4.12.0 ALEOS versions prior to 4.9.5 ALEOS versions prior to 4.4.9
Description The issue is related to a lack of input sanitization in AceManager, which allows for the disclosure of sensitive system information.
Recommendations For versions prior to 4.12.0, update to version 4.12.0 or later. For versions prior to 4.9.5, update to version 4.9.5 or later. For versions prior to 4.4.9, update to version 4.4.9 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11857

Affected Products

Aleos