« Volver al listado

CVE-2019-17445

Estado: ModificadaMedia (5.5)—

An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be forced to copy files from the filesystem to other locations via Symbolic Link Following.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (6)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-17445",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-11-22T18:15:10.907",
  "references": [
    {
      "url": "https://eracent.com/security-bulletin-cve-2019-17445/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://eracent.com/security-bulletin-cve-2019-17445/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-59"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be forced to copy files from the filesystem to other locations via Symbolic Link Following."
    },
    {
      "lang": "es",
      "value": "Se detectó un problema en Eracent en Agente EDA, EPA, EPM, EUA, FLW y SUM versiones hasta 10.2.26. El ejecutable del agente, cuando está instalado para operaciones no root (escaneo), puede ser forzado a copiar archivos del sistema de archivos hacia otras ubicaciones por medio del enlace simbólico siguiente."
    }
  ],
  "lastModified": "2026-06-17T02:23:57.917",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:eracent:eda_agent:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC8DA8D3-8764-41D2-A99C-30AA523473A3",
              "versionEndIncluding": "10.2.26"
            },
            {
              "criteria": "cpe:2.3:a:eracent:epa_agent:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2EEEA80F-003B-4654-B69D-4A916F4FFE06",
              "versionEndIncluding": "10.2.26"
            },
            {
              "criteria": "cpe:2.3:a:eracent:epm_agent:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66239CCC-674E-481B-A712-4DB92DCA03DD",
              "versionEndIncluding": "10.2.26"
            },
            {
              "criteria": "cpe:2.3:a:eracent:eua_agent:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "798F41D5-5775-45A5-B1D8-084B4BA73B91",
              "versionEndIncluding": "10.2.26"
            },
            {
              "criteria": "cpe:2.3:a:eracent:flw_agent:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "046A0AB9-813C-4B9E-9FAE-E3B7DEBD4DFD",
              "versionEndIncluding": "10.2.26"
            },
            {
              "criteria": "cpe:2.3:a:eracent:sum_agent:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1463E937-81D1-465A-888E-909EFD28C4E3",
              "versionEndIncluding": "10.2.26"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}