CVE-2019-19885
Last modified
CVE-2019-19885 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and write configuration data without prior authorization. EPSS estimates a 0.99% chance of exploitation in the next 30 days.
Description
In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and write configuration data without prior authorization. This affects COM465IP, COM465DP, COM465ID, CP700, CP907, and CP915 devices before 4.2.0.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bender | Com465ip Firmware | < 4.2.0 |
| Bender | Com465dp Firmware | < 4.2.0 |
| Bender | Com465id Firmware | < 4.2.0 |
| Bender | Cp700 Firmware | < 4.2.0 |
| Bender | Cp907 Firmware | < 4.2.0 |
| Bender | Cp915 Firmware | < 4.2.0 |
References
- https://cert.vde.com/en-us/advisories/vde-2020-043Third Party Advisory
- https://cert.vde.com/en-us/advisories/vde-2020-043Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-19885?
How severe is CVE-2019-19885?
How do I fix CVE-2019-19885?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-19877An issue was discovered in B&R Industrial Automation APROL b…5.3
- CVE-2019-19878An issue was discovered in B&R Industrial Automation APROL b…7.5
- CVE-2019-19879HashiCorp Sentinel up to 0.10.1 incorrectly parsed negation …7.5
- CVE-2019-1988In sample6 of SkSwizzler.cpp, there is a possible out of bou…
- CVE-2019-19880exprListAppendList in window.c in SQLite 3.30.1 allows attac…7.5
- CVE-2019-19882shadow 4.8, in certain circumstances affecting at least Gent…7.8
- CVE-2019-19886Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker…7.5
- CVE-2019-19887bitstr_tell at bitstr.c in ffjpeg through 2019-08-21 has a N…6.5
- CVE-2019-19888jfif_decode in jfif.c in ffjpeg through 2019-08-21 has a div…6.5
- CVE-2019-19889An issue was discovered on Humax Wireless Voice Gateway HGB1…7.5
- CVE-2019-1989In ih264d_fmt_conv_420sp_to_420p of ih264d_format_conv.c, th…
- CVE-2019-19890An issue was discovered on Humax Wireless Voice Gateway HGB1…7.5
Are you affected by CVE-2019-19885?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
