CRITICAL
Tobesoft Nexacro14 ActiveX File Download Vulnerability
Published May 6, 2020
9.8
CRITICALCVSS 3.1
EPSS 0.75%
Description
Tobesoft Nexacro v2019.9.25.1 and earlier version have an arbitrary code execution vulnerability by using method supported by Nexacro14 ActiveX Control. It allows attacker to cause remote code execution.
Affected products
-
Affected
- ≥ 2019.9.25.1, ≤ 14.0.1.3400
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://support.tobesoft.co.kr/Support/index.html x_refsource_MISCVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-8799 Advisory
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35358 x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://support.tobesoft.co.kr/Support/index.html | x_refsource_MISCVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-8799 | Advisory | |
| https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35358 | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner krcert
Published May 6, 2020
Updated Aug 5, 2024
Reserved Nov 21, 2019
Link CVE-2019-19167
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data