victor Web Client - Arbitrary File Deletion Vulnerability
Published Oct 8, 2020
8.1
HIGHCVSS 3.1
EPSS 1.13%
Description
A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could allow a remote unauthenticated attacker on the network to delete arbitrary files on the system or render the system unusable by conducting a Denial of Service attack.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<=5.4.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Johnson Controls | victor Web Client version 5.4.1 and prior | n/a |
|
- ≤ 5.4.1
- ≤ 2.80
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade all versions of victor Web Client to v5.6
Registered users can obtain the critical software update by downloading the update found here: https://www.americandynamics.net/support/SoftwareDownloads.aspx.
References (2)
- https://us-cert.cisa.gov/ics/advisories/icsa-20-282-01 third-party-advisoryx_refsource_CERTMitigationThird Party AdvisoryUS Government Resource
- https://www.johnsoncontrols.com/cyber-solutions/security-advisories x_refsource_CONFIRMPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://us-cert.cisa.gov/ics/advisories/icsa-20-282-01 | third-party-advisoryx_refsource_CERTMitigationThird Party AdvisoryUS Government Resource | |
| https://www.johnsoncontrols.com/cyber-solutions/security-advisories | x_refsource_CONFIRMPatchThird Party Advisory |
Change history (0)
No recorded changes yet.