← Back

CVE-2019-19460

nvd nist
Published: Dec 3, 2019Modified: Nov 21, 2024

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local SYSTEM permissions by default. This is against the principle of least privilege. An attacker who is able to exploit CVE-2019-19458 or CVE-2019-19459 is basically able to write to every single path on the file system, because the webserver is running with the highest privileges available.

Affected (1)

1 product
Proaccess Space
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 5.5
Running on/withPlatform Versions
Microsoft
Windows
All versions

Timeline

No history available yet.