{"api_version":"1","generated_at":"2026-07-23T23:23:27+00:00","cve":"CVE-2019-6026","urls":{"html":"https://cve.report/CVE-2019-6026","api":"https://cve.report/api/cve/CVE-2019-6026.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-6026","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-6026"},"summary":{"title":"CVE-2019-6026","description":"Privilege escalation vulnerability in Multiple MOTEX products (LanScope Cat client program (MR) and LanScope Cat client program (MR)LanScope Cat detection agent (DA) prior to Ver.9.2.1.0, LanScope Cat server monitoring agent (SA, SAE) prior to Ver.9.2.2.0, LanScope An prior to Ver 2.7.7.0 (LanScope An 2 series), and LanScope An prior to Ver 3.0.8.1 (LanScope An 3 series)) allow authenticated attackers to obtain unauthorized privileges and execute arbitrary code.","state":"PUBLIC","assigner":"vultures@jpcert.or.jp","published_at":"2019-12-26 16:15:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"http://jvn.jp/en/jp/JVN49068796/index.html","name":"http://jvn.jp/en/jp/JVN49068796/index.html","refsource":"MISC","tags":["Third Party Advisory"],"title":"JVN#49068796: Multiple MOTEX products vulnerable to privilege escalation","mime":"text/xml","httpstatus":"200","archivestatus":"0"},{"url":"https://www.motex.co.jp/news/news_topics/2019/release191202/","name":"https://www.motex.co.jp/news/news_topics/2019/release191202/","refsource":"MISC","tags":["Vendor Advisory"],"title":"【重要なお知らせ】LanScope Cat/Anにおける権限昇格の脆弱性について（CVE-2019-6026）   – MOTEX Inc.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-6026","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-6026","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"6026","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"motex","cpe5":"lanscope_an","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6026","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"motex","cpe5":"lanscope_an","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6026","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"motex","cpe5":"lanscope_an","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6026","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"motex","cpe5":"lanscope_an","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6026","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"motex","cpe5":"lanscope_cat_client_program","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6026","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"motex","cpe5":"lanscope_cat_client_program","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6026","vulnerable":"1","versionEndIncluding":"9.0.1.9","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"motex","cpe5":"lanscope_cat_client_program","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6026","vulnerable":"1","versionEndIncluding":"9.1.0.8","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"motex","cpe5":"lanscope_cat_client_program","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6026","vulnerable":"1","versionEndIncluding":"9.2.0.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"motex","cpe5":"lanscope_cat_client_program","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6026","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"motex","cpe5":"lanscope_cat_detection_agent","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6026","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"motex","cpe5":"lanscope_cat_detection_agent","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6026","vulnerable":"1","versionEndIncluding":"9.0.1.9","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"motex","cpe5":"lanscope_cat_detection_agent","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6026","vulnerable":"1","versionEndIncluding":"9.1.0.8","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"motex","cpe5":"lanscope_cat_detection_agent","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6026","vulnerable":"1","versionEndIncluding":"9.2.0.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"motex","cpe5":"lanscope_cat_detection_agent","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6026","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"motex","cpe5":"lanscope_cat_server_monitoring_agent","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6026","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"motex","cpe5":"lanscope_cat_server_monitoring_agent","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-6026","ASSIGNER":"vultures@jpcert.or.jp","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"MOTEX.Inc","product":{"product_data":[{"product_name":"Multiple MOTEX products","version":{"version_data":[{"version_value":"LanScope Cat client program (MR) and LanScope Cat client program (MR)LanScope Cat detection agent (DA) prior to Ver.9.2.1.0, LanScope Cat server monitoring agent (SA, SAE) prior to Ver.9.2.2.0, LanScope An prior to Ver 2.7.7.0 (LanScope An 2 series), and LanScope An prior to Ver 3.0.8.1 (LanScope An 3 series)"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Privilege escalation"}]}]},"references":{"reference_data":[{"url":"https://www.motex.co.jp/news/news_topics/2019/release191202/","refsource":"MISC","name":"https://www.motex.co.jp/news/news_topics/2019/release191202/"},{"url":"http://jvn.jp/en/jp/JVN49068796/index.html","refsource":"MISC","name":"http://jvn.jp/en/jp/JVN49068796/index.html"}]},"description":{"description_data":[{"lang":"eng","value":"Privilege escalation vulnerability in Multiple MOTEX products (LanScope Cat client program (MR) and LanScope Cat client program (MR)LanScope Cat detection agent (DA) prior to Ver.9.2.1.0, LanScope Cat server monitoring agent (SA, SAE) prior to Ver.9.2.2.0, LanScope An prior to Ver 2.7.7.0 (LanScope An 2 series), and LanScope An prior to Ver 3.0.8.1 (LanScope An 3 series)) allow authenticated attackers to obtain unauthorized privileges and execute arbitrary code."}]}},"nvd":{"publishedDate":"2019-12-26 16:15:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":7.2},"severity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:motex:lanscope_an:*:*:*:*:*:*:*:*","versionStartIncluding":"2.0.0.0","versionEndExcluding":"2.7.7.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:motex:lanscope_cat_server_monitoring_agent:*:*:*:*:*:*:*:*","versionEndExcluding":"9.2.2.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:motex:lanscope_cat_detection_agent:*:*:*:*:*:*:*:*","versionStartIncluding":"9.2.0.0","versionEndIncluding":"9.2.0.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:motex:lanscope_cat_detection_agent:*:*:*:*:*:*:*:*","versionStartIncluding":"9.1.0.0","versionEndIncluding":"9.1.0.8","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:motex:lanscope_cat_detection_agent:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0.0.0","versionEndIncluding":"9.0.1.9","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:motex:lanscope_cat_detection_agent:*:*:*:*:*:*:*:*","versionEndExcluding":"8.4.3.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:motex:lanscope_cat_client_program:*:*:*:*:*:*:*:*","versionEndExcluding":"8.4.3.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:motex:lanscope_cat_client_program:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0.0.0","versionEndIncluding":"9.0.1.9","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:motex:lanscope_cat_client_program:*:*:*:*:*:*:*:*","versionStartIncluding":"9.1.0.0","versionEndIncluding":"9.1.0.8","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:motex:lanscope_cat_client_program:*:*:*:*:*:*:*:*","versionStartIncluding":"9.2.0.0","versionEndIncluding":"9.2.0.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:motex:lanscope_an:*:*:*:*:*:windows:*:*","versionStartIncluding":"3.0.0.0","versionEndExcluding":"3.0.8.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"6026","Ordinal":"143680","Title":"CVE-2019-6026","CVE":"CVE-2019-6026","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"6026","Ordinal":"1","NoteData":"Privilege escalation vulnerability in Multiple MOTEX products (LanScope Cat client program (MR) and LanScope Cat client program (MR)LanScope Cat detection agent (DA) prior to Ver.9.2.1.0, LanScope Cat server monitoring agent (SA, SAE) prior to Ver.9.2.2.0, LanScope An prior to Ver 2.7.7.0 (LanScope An 2 series), and LanScope An prior to Ver 3.0.8.1 (LanScope An 3 series)) allow authenticated attackers to obtain unauthorized privileges and execute arbitrary code.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"6026","Ordinal":"2","NoteData":"2019-12-26","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"6026","Ordinal":"3","NoteData":"2019-12-26","Type":"Other","Title":"Modified"}]}}}