Vulnerability Description
In IXP EasyInstall 6.2.13723, there is Remote Code Execution via the Agent Service. An unauthenticated attacker can communicate with the Agent Service over TCP port 20051, and execute code in the NT AUTHORITY\SYSTEM context of the target system by using the Execute Command Line function.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ixpdata | Easyinstall | 6.2.13723 |
Related Weaknesses (CWE)
References
- https://improsec.com/tech-blog/multiple-vulnerabilities-in-easyinstall-rmm-and-dExploitThird Party Advisory
- https://improsec.com/tech-blog/multiple-vulnerabilities-in-easyinstall-rmm-and-dExploitThird Party Advisory
FAQ
What is CVE-2019-19897?
CVE-2019-19897 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In IXP EasyInstall 6.2.13723, there is Remote Code Execution via the Agent Service. An unauthenticated attacker can communicate with the Agent Service over TCP port 20051, and execute code in the NT A...
How severe is CVE-2019-19897?
CVE-2019-19897 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-19897?
Check the references section above for vendor advisories and patch information. Affected products include: Ixpdata Easyinstall.