RSS   Vulnerabilities for 'Viaware'   RSS

2021-08-31
 
CVE-2021-36356

CWE-434
 

 
KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames (even though browseSystemFiles.php is no longer reachable via the GUI). NOTE: this issue exists because of an incomplete fix for CVE-2019-17124.

 
2021-07-12
 
CVE-2021-35064

CWE-269
 

 
KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits running of multiple dangerous commands, including unzip, systemctl and dpkg.

 
2019-10-09
 
CVE-2019-17124

CWE-276
 

 
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.

 


Copyright 2021, cxsecurity.com

 

Back to Top