CVE-2019-11029
Last modified
CVE-2019-11029 is a vulnerability of currently unknown severity. Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Download() method of AutoUpdateService in SMServer.exe, leading to Directory Traversal. An attacker could use ..\ with this method to iterate over lists of interesting system files and download them without previous authentication. EPSS estimates a 2.44% chance of exploitation in the next 30 days.
Description
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Download() method of AutoUpdateService in SMServer.exe, leading to Directory Traversal. An attacker could use ..\ with this method to iterate over lists of interesting system files and download them without previous authentication. This includes SAM-database backups, Web.config files, etc. and might cause a serious impact on confidentiality.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mirasys | Mirasys Vms | < 7.6.1 |
| Mirasys | Mirasys Vms | >= 8.0.0, < 8.3.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-11029?
How severe is CVE-2019-11029?
How do I fix CVE-2019-11029?
Are you affected by CVE-2019-11029?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
