Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-19460

Опубликовано: 03 дек. 2019
Источник: nvd
CVSS3: 5.5
CVSS2: 6.6
EPSS Низкий

Описание

An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local SYSTEM permissions by default. This is against the principle of least privilege. An attacker who is able to exploit CVE-2019-19458 or CVE-2019-19459 is basically able to write to every single path on the file system, because the webserver is running with the highest privileges available.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:saltosystem:proaccess_space:*:*:*:*:*:*:*:*
Версия до 5.5 (включая)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

EPSS

Процентиль: 25%
0.00086
Низкий

5.5 Medium

CVSS3

6.6 Medium

CVSS2

Дефекты

CWE-276

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local SYSTEM permissions by default. This is against the principle of least privilege. An attacker who is able to exploit CVE-2019-19458 or CVE-2019-19459 is basically able to write to every single path on the file system, because the webserver is running with the highest privileges available.

EPSS

Процентиль: 25%
0.00086
Низкий

5.5 Medium

CVSS3

6.6 Medium

CVSS2

Дефекты

CWE-276