{"api_version":"1","generated_at":"2026-07-23T10:59:32+00:00","cve":"CVE-2019-19994","urls":{"html":"https://cve.report/CVE-2019-19994","api":"https://cve.report/api/cve/CVE-2019-19994.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-19994","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-19994"},"summary":{"title":"CVE-2019-19994","description":"An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows blind Command Injection. An attacker without authentication is able to execute arbitrary operating system command by injecting the vulnerable parameter in the PHP Web page /common/vam_monitor_sap.php.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-02-26 16:15:00","updated_at":"2020-02-27 13:32:00"},"problem_types":["CWE-78"],"metrics":[],"references":[{"url":"https://www.seling.it/","name":"https://www.seling.it/","refsource":"MISC","tags":["Product"],"title":"Controllo accessi, rilevazione presenze e Building Security - Selesta Ingegneria","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.seling.it/product/vam/","name":"https://www.seling.it/product/vam/","refsource":"MISC","tags":["Product","Vendor Advisory"],"title":"Applicativo Controllo Accessi: VAM - Selesta Ingegneria","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.telecomitalia.com/tit/it/innovazione/cybersecurity/red-team.html","name":"https://www.telecomitalia.com/tit/it/innovazione/cybersecurity/red-team.html","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Gruppo TIM | Vulnerability Research & Advisor","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-19994","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-19994","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"19994","vulnerable":"1","versionEndIncluding":"4.29.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"seling","cpe5":"visual_access_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-19994","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows blind Command Injection. An attacker without authentication is able to execute arbitrary operating system command by injecting the vulnerable parameter in the PHP Web page /common/vam_monitor_sap.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://www.telecomitalia.com/tit/it/innovazione/cybersecurity/red-team.html","url":"https://www.telecomitalia.com/tit/it/innovazione/cybersecurity/red-team.html"},{"url":"https://www.seling.it/","refsource":"MISC","name":"https://www.seling.it/"},{"url":"https://www.seling.it/product/vam/","refsource":"MISC","name":"https://www.seling.it/product/vam/"}]}},"nvd":{"publishedDate":"2020-02-26 16:15:00","lastModifiedDate":"2020-02-27 13:32:00","problem_types":["CWE-78"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":10},"severity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:seling:visual_access_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15.0","versionEndIncluding":"4.29.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"19994","Ordinal":"163820","Title":"CVE-2019-19994","CVE":"CVE-2019-19994","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"19994","Ordinal":"1","NoteData":"An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows blind Command Injection. An attacker without authentication is able to execute arbitrary operating system command by injecting the vulnerable parameter in the PHP Web page /common/vam_monitor_sap.php.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"19994","Ordinal":"2","NoteData":"2020-02-26","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"19994","Ordinal":"3","NoteData":"2020-02-26","Type":"Other","Title":"Modified"}]}}}