CVE-2019-6026
Last modified
CVE-2019-6026 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Privilege escalation vulnerability in Multiple MOTEX products (LanScope Cat client program (MR) and LanScope Cat client program (MR)LanScope Cat detection agent (DA) prior to Ver.9.2.1.0, LanScope Cat server monitoring agent (SA, SAE) prior to Ver.9.2.2.0, LanScope An prior to Ver 2.7.7.0 (LanScope An 2 series), and LanScope An prior to Ver 3.0.8.1 (LanScope An 3 series)) allow authenticated attackers to obtain unauthorized privileges and execute arbitrary code.. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
Privilege escalation vulnerability in Multiple MOTEX products (LanScope Cat client program (MR) and LanScope Cat client program (MR)LanScope Cat detection agent (DA) prior to Ver.9.2.1.0, LanScope Cat server monitoring agent (SA, SAE) prior to Ver.9.2.2.0, LanScope An prior to Ver 2.7.7.0 (LanScope An 2 series), and LanScope An prior to Ver 3.0.8.1 (LanScope An 3 series)) allow authenticated attackers to obtain unauthorized privileges and execute arbitrary code.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Motex | Lanscope An | >= 2.0.0.0, < 2.7.7.0 |
| Motex | Lanscope An | >= 3.0.0.0, < 3.0.8.1 |
| Motex | Lanscope Cat Client Program | < 8.4.3.2 |
| Motex | Lanscope Cat Client Program | >= 9.0.0.0, <= 9.0.1.9 |
| Motex | Lanscope Cat Client Program | >= 9.1.0.0, <= 9.1.0.8 |
| Motex | Lanscope Cat Client Program | >= 9.2.0.0, <= 9.2.0.3 |
| Motex | Lanscope Cat Detection Agent | < 8.4.3.2 |
| Motex | Lanscope Cat Detection Agent | >= 9.0.0.0, <= 9.0.1.9 |
| Motex | Lanscope Cat Detection Agent | >= 9.1.0.0, <= 9.1.0.8 |
| Motex | Lanscope Cat Detection Agent | >= 9.2.0.0, <= 9.2.0.3 |
| Motex | Lanscope Cat Server Monitoring Agent | < 9.2.2.0 |
References
- http://jvn.jp/en/jp/JVN49068796/index.htmlThird Party Advisory
- https://www.motex.co.jp/news/news_topics/2019/release191202/Vendor Advisory
- http://jvn.jp/en/jp/JVN49068796/index.htmlThird Party Advisory
- https://www.motex.co.jp/news/news_topics/2019/release191202/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-6026?
How severe is CVE-2019-6026?
How do I fix CVE-2019-6026?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-6020Open redirect vulnerability in PowerCMS 5.12 and earlier (Po…6.1
- CVE-2019-6021Open redirect vulnerability in Library Information Managemen…6.1
- CVE-2019-6022Directory traversal vulnerability in Cybozu Office 10.0.0 to…6.5
- CVE-2019-6023Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated a…4.3
- CVE-2019-6024Rakuma App for Android version 7.15.0 and earlier, and for i…6.5
- CVE-2019-6025Open redirect vulnerability in Movable Type series Movable T…6.1
- CVE-2019-6027Cross-site request forgery (CSRF) vulnerability in WP Spell …8.8
- CVE-2019-6029Cross-site scripting vulnerability in Custom Body Class 0.6.…6.1
- CVE-2019-6030Cross-site request forgery (CSRF) vulnerability in Custom Bo…8.8
- CVE-2019-6031Cross-site scripting vulnerability in KINZA for Windows vers…6.1
- CVE-2019-6032The NTV News24 prior to Ver.3.0.0 does not verify X.509 cert…7.4
- CVE-2019-6033Cross-site scripting vulnerability in a-blog cms versions pr…6.1
Are you affected by CVE-2019-6026?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
