6.4
CVSSv2

CVE-2018-15486

Published: 07/09/2018 Updated: 03/10/2019
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

An issue exists on KONE Group Controller (KGC) devices prior to 4.6.5. Unauthenticated Local File Inclusion and File modification is possible through the open HTTP interface by modifying the name parameter of the file endpoint, aka KONE-02.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kone group_controller_firmware

Exploits

KONE KGC versions 464 and below suffer from unauthenticated remote code execution, denial of service, local file inclusion, and missing FTP access control vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Vulnerabilities in KONEs Group Controller (KGC) <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Sebastian ...