ZeroHour

CVE-2019-17445

CVSS 3.1
5.5 medium
EPSS
<1%p27
Published
()
Modified
Description

An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be forced to copy files from the filesystem to other locations via Symbolic Link Following.

Vendors
eracent
Products
eda agent, epa agent, epm agent, eua agent, flw agent, sum agent
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.