CVE-2019-13547: Advantech WISE-PaaS/RMM NodeRed Server Missing Authentication Remote Code Execution Vulnerability
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the function without authentication.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Advantech WISE-PaaS/RMM. Authentication is not required to exploit this vulnerability. The specific flaw exists within the NodeRed Server, which listens on TCP port 1880 by default. The issue results from the lack of authentication prior to allowing alterations to the system configuration. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-13547?
CVE-2019-13547 has a critical severity level due to the potential for remote code execution.
How do I fix CVE-2019-13547?
To remediate CVE-2019-13547, update to a version of Advantech WISE-PaaS/RMM later than 3.3.29 that addresses this vulnerability.
What type of vulnerability is CVE-2019-13547?
CVE-2019-13547 is categorized as an authentication-related vulnerability, allowing unauthorized access to functions.
Who is affected by CVE-2019-13547?
CVE-2019-13547 affects users of Advantech WISE-PaaS/RMM versions 3.3.29 and prior.
Can CVE-2019-13547 be exploited remotely?
Yes, CVE-2019-13547 can be exploited remotely if an attacker can access the vulnerable system's IP address.