PoC Index

CVE-2019-19994

HIGH 10.0EPSS 4.8%

An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows blind Command Injection. An attacker without authentication is able to execute arbitrary operating system command by injecting the vulnerable parameter in the PHP Web page /common/vam_monitor_sap.php.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
4.84% chance of exploitation in the next 30 days, 91th percentile
Published
2020-02-26
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related