CVE-2019-13285: High severity cososys endpoint protector vulnerability
Published May 4, 2020
·Updated
CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.
Affected Software
1 affected component
CoSoSys Endpoint Protector=5.1.0.2
Event History
May 4, 2020
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13285?
CVE-2019-13285 has a medium severity rating due to its potential for host header injection vulnerabilities.
2
How do I fix CVE-2019-13285?
To fix CVE-2019-13285, upgrade to a patched version of CoSoSys Endpoint Protector that addresses the host header injection issue.
3
What systems are affected by CVE-2019-13285?
CVE-2019-13285 affects CoSoSys Endpoint Protector version 5.1.0.2.
4
What is host header injection in relation to CVE-2019-13285?
Host header injection in CVE-2019-13285 refers to an attacker exploiting the application to manipulate how it processes HTTP host headers.
5
Can CVE-2019-13285 lead to further attacks?
Yes, CVE-2019-13285 could lead to further attacks such as web cache poisoning or redirecting users to malicious sites.