← Back

Viaware

viaware

Vendor: Kramerav • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kramerav
1Viaware
Nov 21, 2024
Aug 31, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames (even though browseSystemFiles.php is no longer re...Show more
KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames (even though browseSystemFiles.php is no longer reachable via the GUI). NOTE: this issue exists because of an incomplete fix for CVE-2019-17124.Show less
1Kramerav
1Viaware
Nov 21, 2024
Jul 12, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits running of multiple dangerous commands, including unzip, systemctl and dpkg.
1Kramerav
1Viaware
Nov 21, 2024
Oct 9, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.