PT-2021-17317 · Visualware · Visualware Myconnection Server
B0Yd
+1
·
Published
2021-02-26
·
Updated
2023-10-25
·
CVE-2021-27198
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Visualware MyConnection Server versions prior to 11.1a
Description:
An issue was discovered in Visualware MyConnection Server that allows Unauthenticated Remote Code Execution via Arbitrary File Upload in the web service when using a "myspeed/sf?filename=" URI. This application is written in Java and is thus cross-platform. The Windows installation runs as SYSTEM, which means that exploitation gives one Administrator privileges on the target system.
Recommendations:
For versions prior to 11.1a, update to version 11.1a or later to resolve the issue. As a temporary workaround, consider restricting access to the "myspeed/sf" API endpoint to minimize the risk of exploitation. Avoid using the
filename parameter in the affected API endpoint until the issue is resolved.Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Visualware Myconnection Server