CVE-2019-14453
Last modified
CVE-2019-14453 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. An issue was discovered in Comelit "App lejos de casa (web)" 2.8.0. It allows privilege escalation via modified domus and logged fields, related to js/bridge.min.js and login.json. EPSS estimates a 1.23% chance of exploitation in the next 30 days.
Description
An issue was discovered in Comelit "App lejos de casa (web)" 2.8.0. It allows privilege escalation via modified domus and logged fields, related to js/bridge.min.js and login.json. For example, an attacker can achieve high privileges (installer or administrator) for the graphical interface via a 1C000000000S value for domus, in conjunction with a zero value for logged.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Comelitgroup | Away From Home | 2.8.0 |
References
- https://www.blogx86.net/2021/07/26/cve-2019-14453/Exploit, Third Party Advisory
- https://www.blogx86.net/2021/07/26/cve-2019-14453/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-14453?
How severe is CVE-2019-14453?
How do I fix CVE-2019-14453?
Are you affected by CVE-2019-14453?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
