CVE-2019-7590
exacqVision Server Unquoted Service Path
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
ExacqVision Server’s services 'exacqVisionServer', 'dvrdhcpserver' and 'mdnsresponder' have an unquoted service path. If an authenticated user is able to insert code in their system root path it potentially can be executed during the application startup. This could allow the authenticated user to elevate privileges on the system. This issue affects: Exacq Technologies, Inc. exacqVision Server 9.6; 9.8. This issue does not affect: Exacq Technologies, Inc. exacqVision Server version 9.4 and prior versions; 19.03. It is not known whether this issue affects: Exacq Technologies, Inc. exacqVision Server versions prior to 8.4.
Los servicios de exacqVision Server 'exacqVisionServer', 'dvrdhcpserver' y 'mdnsresponder' tienen una ruta de servicio sin comillas. Si un usuario autenticado puede insertar código en la ruta raíz de su sistema, puede ejecutarse potencialmente durante el inicio de la aplicación. Esto podría permitir al usuario autenticado elevar los privilegios en el sistema. Este problema afecta a: Exacq Technologies, Inc. exacqVision Server 9.6; 9.8 Este problema no afecta: Exacq Technologies, Inc. exacqVision Server versión 9.4 y versiones anteriores; 19.03. No se sabe si este problema afecta: Exacq Technologies, Inc. exacqVision Server versiones anteriores a 8.4
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-02-07 CVE Reserved
- 2019-07-19 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-428: Unquoted Search Path or Element
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/109307 | Third Party Advisory | |
https://www.us-cert.gov/ics/advisories/icsa-19-199-01 | Third Party Advisory | |
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5515.php | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://packetstormsecurity.com/files/152128/exacqVision-9.8-Unquoted-Service-Path-Privilege-Escalation.html | 2024-09-17 |
URL | Date | SRC |
---|---|---|
https://gallery.technet.microsoft.com/scriptcenter/Windows-Unquoted-Service-190f0341 | 2020-02-10 |
URL | Date | SRC |
---|---|---|
https://www.johnsoncontrols.com/cyber-solutions/security-advisories | 2020-02-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Johnsoncontrols Search vendor "Johnsoncontrols" | Exacqvision Server Search vendor "Johnsoncontrols" for product "Exacqvision Server" | 9.6 Search vendor "Johnsoncontrols" for product "Exacqvision Server" and version "9.6" | - |
Affected
| ||||||
Johnsoncontrols Search vendor "Johnsoncontrols" | Exacqvision Server Search vendor "Johnsoncontrols" for product "Exacqvision Server" | 9.8 Search vendor "Johnsoncontrols" for product "Exacqvision Server" and version "9.8" | - |
Affected
|