eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.
The vulnerability results from improper implementation of access control mechanisms in the acteScanAVReport module of the eScan management console. An attacker can send a specially crafted network request without the need for authentication, as the application does not properly verify permissions to access this component. The attack vector is network-based, requires no user interaction or special privileges, making this vulnerability particularly dangerous.
An attacker can gain unauthorized access to sensitive data, modify data or system configuration, and potentially cause service unavailability — corresponding to complete breach of confidentiality, integrity, and availability (C:H/I:H/A:H).
Apply patches available from the vendor according to references. It is also recommended to restrict access to the eScan management console at the network level (firewall) exclusively to trusted IP addresses until the fix is deployed.
eScan Management Console version 14.0.1400.2281
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HEscanav Escan Management Console
APPEscanav14.0.1400.2281
Related vulnerabilities
Privilege Escalation w eScan Management Console — hasła w plain text
XSS w formularzu edycji użytkownika eScan Management Console
SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote att...
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allo...
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allo...