MEDIUM🇵🇱 Wersja polska

CVE-2019-7590

CVSS 6.7v3.0pub. 2019-07-19upd. 2024-11-21

ExacqVision Server’s services 'exacqVisionServer', 'dvrdhcpserver' and 'mdnsresponder' have an unquoted service path. If an authenticated user is able to insert code in their system root path it potentially can be executed during the application startup. This could allow the authenticated user to elevate privileges on the system. This issue affects: Exacq Technologies, Inc. exacqVision Server 9.6; 9.8. This issue does not affect: Exacq Technologies, Inc. exacqVision Server version 9.4 and prior versions; 19.03. It is not known whether this issue affects: Exacq Technologies, Inc. exacqVision Server versions prior to 8.4.

CVSS Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
  • Johnsoncontrols Exacqvision Server

    APP
    Johnsoncontrols
    9.69.8
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-32758CRITICAL9.0PL ✓same product

Niewystarczająca długość klucza kryptograficznego w komunikacji exacqVision

CVE-2021-27665HIGH7.5same product

An unauthenticated remote user could exploit a potential integer overflow condition in the exacqVision Server ...

CVE-2024-32865MEDIUM6.4same product

Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by con...

CVE-2023-4804CRITICAL10.0PL ✓same vendor

Niezamierzone ujawnienie funkcji debug w Johnson Controls Quantum HD Unity

CVE-2023-2024CRITICAL10.0PL ✓same vendor

Pominięcie uwierzytelnienia w Johnson Controls OpenBlue Enterprise Manager Data Collector