PoC Index

CVE-2019-19459

CRITICAL 9.8EPSS 3.5%

An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary commands on the server.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
3.51% chance of exploitation in the next 30 days, 88th percentile
Published
2019-12-03
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related