Vulnerabilities > Ixpdata > Easyinstall > 6.2.13723

DATE CVE VULNERABILITY TITLE RISK
2020-01-23 CVE-2019-19898 Use of Hard-coded Credentials vulnerability in Ixpdata Easyinstall 6.2.13723
In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotely.
network
low complexity
ixpdata CWE-798
5.0
2020-01-23 CVE-2019-19897 OS Command Injection vulnerability in Ixpdata Easyinstall 6.2.13723
In IXP EasyInstall 6.2.13723, there is Remote Code Execution via the Agent Service.
network
low complexity
ixpdata CWE-78
critical
10.0
2020-01-23 CVE-2019-19896 Incorrect Default Permissions vulnerability in Ixpdata Easyinstall 6.2.13723
In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share.
network
low complexity
ixpdata CWE-276
critical
9.0
2020-01-23 CVE-2019-19895 Improper Input Validation vulnerability in Ixpdata Easyinstall 6.2.13723
In IXP EasyInstall 6.2.13723, there is Lateral Movement (using the Agent Service) against other users on a client system.
local
low complexity
ixpdata CWE-20
4.6
2020-01-23 CVE-2019-19894 Improper Input Validation vulnerability in Ixpdata Easyinstall 6.2.13723
In IXP EasyInstall 6.2.13723, it is possible to temporarily disable UAC by using the Agent Service on a client system.
local
low complexity
ixpdata CWE-20
2.1
2020-01-23 CVE-2019-19893 Path Traversal vulnerability in Ixpdata Easyinstall 6.2.13723
In IXP EasyInstall 6.2.13723, there is Directory Traversal on TCP port 8000 via the Engine Service by an unauthenticated attacker, who can access the server's filesystem with the access rights of NT AUTHORITY\SYSTEM.
network
low complexity
ixpdata CWE-22
7.8