ZeroHour

CVE-2018-15486

PoC
CVSS 3.0
9.1 critical
EPSS
2%p80
Published
()
Modified
Description

An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Unauthenticated Local File Inclusion and File modification is possible through the open HTTP interface by modifying the name parameter of the file endpoint, aka KONE-02.

Vendors
kone
Products
group controller firmware
Weakness
CWE-829
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.