MEDIUM🇬🇧 English

CVE-2019-7590

CVSS 6.7v3.0pub. 2019-07-19upd. 2024-11-21

ExacqVision Server’s services 'exacqVisionServer', 'dvrdhcpserver' and 'mdnsresponder' have an unquoted service path. If an authenticated user is able to insert code in their system root path it potentially can be executed during the application startup. This could allow the authenticated user to elevate privileges on the system. This issue affects: Exacq Technologies, Inc. exacqVision Server 9.6; 9.8. This issue does not affect: Exacq Technologies, Inc. exacqVision Server version 9.4 and prior versions; 19.03. It is not known whether this issue affects: Exacq Technologies, Inc. exacqVision Server versions prior to 8.4.

oryginał EN
CVSS Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
  • Johnsoncontrols Exacqvision Server

    APP
    Johnsoncontrols
    9.69.8
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2024-32758CRITICAL9.0PL ✓ten sam produkt

Niewystarczająca długość klucza kryptograficznego w komunikacji exacqVision

CVE-2021-27665HIGH7.5ten sam produkt

An unauthenticated remote user could exploit a potential integer overflow condition in the exacqVision Server ...

CVE-2024-32865MEDIUM6.4ten sam produkt

Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by con...

CVE-2023-4804CRITICAL10.0PL ✓ten sam vendor

Niezamierzone ujawnienie funkcji debug w Johnson Controls Quantum HD Unity

CVE-2023-2024CRITICAL10.0PL ✓ten sam vendor

Pominięcie uwierzytelnienia w Johnson Controls OpenBlue Enterprise Manager Data Collector