5.5
CVSSv3

CVE-2019-17445

Published: 22/11/2019 Updated: 04/12/2019
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent up to and including 10.2.26. The agent executable, when installed for non-root operations (scanning), can be forced to copy files from the filesystem to other locations via Symbolic Link Following.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

eracent eda_agent

eracent epa_agent

eracent epm_agent

eracent eua_agent

eracent flw_agent

eracent sum_agent