First published: Fri Sep 06 2019(Updated: )
In Pyxis ES Versions 1.3.4 through to 1.6.1 and Pyxis Enterprise Server, with Windows Server Versions 4.4 through 4.12, a vulnerability has been identified where existing access privileges are not restricted in coordination with the expiration of access based on active directory user account changes when the device is joined to an AD domain.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Bd Pyxis Enterprise Server | >=4.4<=4.12 | |
Bd Pyxis Es | >=1.3.4<=1.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13517 is a vulnerability in Pyxis ES versions 1.3.4 through 1.6.1 and Pyxis Enterprise Server with Windows Server versions 4.4 through 4.12.
The severity of CVE-2019-13517 is high, with a severity value of 8.8.
The affected software for CVE-2019-13517 includes Pyxis ES versions 1.3.4 through 1.6.1 and Pyxis Enterprise Server with Windows Server versions 4.4 through 4.12.
CVE-2019-13517 allows existing access privileges to not be restricted in coordination with the expiration of access based on active directory user account changes.
Yes, you can find more information about CVE-2019-13517 at the following link: [https://www.us-cert.gov/ics/advisories/icsma-19-248-01](https://www.us-cert.gov/ics/advisories/icsma-19-248-01).