ZeroHour

CVE-2019-11526

PoC
CVSS 3.1
9.8 critical
EPSS
2%p79
Published
()
Modified
Description

An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable to file path injection. This enables the Attacker to write files with superuser privileges in specific locations.

Vendors
softing
Products
uagate si firmware
Weakness
CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.