First published: Thu Oct 31 2019(Updated: )
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a lack of proper validation of a user-supplied path prior to use in file operations. An attacker can leverage these vulnerabilities to remotely execute code while posing as an administrator.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech WISE-PaaS/RMM | ||
Advantech WISE-PaaS/RMM | <=3.3.29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13551 has been classified as a high-severity vulnerability due to its potential for remote code execution.
To fix CVE-2019-13551, upgrade to a version of Advantech WISE-PaaS/RMM that is higher than 3.3.29.
CVE-2019-13551 is caused by improper validation of user-supplied paths before they are used in file operations.
Advantech WISE-PaaS/RMM versions 3.3.29 and prior are affected by CVE-2019-13551.
Yes, CVE-2019-13551 can be exploited remotely by an attacker posing as an administrator.