CVE-2019-19893
Summary
| CVE | CVE-2019-19893 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-23 21:15:00 UTC |
| Updated | 2020-01-29 20:50:00 UTC |
| Description | In IXP EasyInstall 6.2.13723, there is Directory Traversal on TCP port 8000 via the Engine Service by an unauthenticated attacker, who can access the server's filesystem with the access rights of NT AUTHORITY\SYSTEM. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ixpdata | Easyinstall | 6.2.13723 | All | All | All |
| Application | Ixpdata | Easyinstall | 6.2.13723 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple vulnerabilities in EasyInstall RMM and deployment software — Improsec | improving security | MISC | improsec.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.