CVE-2019-11029
Summary
| CVE | CVE-2019-11029 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-22 15:15:00 UTC |
| Updated | 2019-08-30 12:55:00 UTC |
| Description | Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Download() method of AutoUpdateService in SMServer.exe, leading to Directory Traversal. An attacker could use ..\ with this method to iterate over lists of interesting system files and download them without previous authentication. This includes SAM-database backups, Web.config files, etc. and might cause a serious impact on confidentiality. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mirasys | Mirasys Vms | All | All | All | All |
| Application | Mirasys | Mirasys Vms | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Vulnerabilities in Mirasys VMS video management solution | NCSC-FI | MISC | www.kyberturvallisuuskeskus.fi | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.