Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mx3h-2chv-mcx2

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows remote attackers to execute arbitrary code via vectors related to creation of a file, loading a DLL, and process control.

CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows remote attackers to execute arbitrary code via vectors related to creation of a file, loading a DLL, and process control.

EPSS

Процентиль: 99%
0.73429
Высокий

Дефекты

CWE-287

Связанные уязвимости

nvd
около 14 лет назад

CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows remote attackers to execute arbitrary code via vectors related to creation of a file, loading a DLL, and process control.

EPSS

Процентиль: 99%
0.73429
Высокий

Дефекты

CWE-287