Lucene search

K
cveMitreCVE-2019-20451
HistoryFeb 10, 2020 - 3:15 p.m.

CVE-2019-20451

2020-02-1015:15:21
CWE-434
mitre
web.nvd.nist.gov
40
cve-2019-20451
http api
prismview system
remote code execution
rebootsystem.lnk
authentication
xml file
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.017

Percentile

88.0%

The HTTP API in Prismview System 9 11.10.17.00 and Prismview Player 11 13.09.1100 allows remote code execution by uploading RebootSystem.lnk and requesting /REBOOTSYSTEM or /RESTARTVNC. (Authentication is required but an XML file containing credentials can be downloaded.)

Affected configurations

Nvd
Node
samsungprismview_player_11Match13.09.1100
OR
samsungprismview_system_9Match11.10.17.00
VendorProductVersionCPE
samsungprismview_player_1113.09.1100cpe:2.3:a:samsung:prismview_player_11:13.09.1100:*:*:*:*:*:*:*
samsungprismview_system_911.10.17.00cpe:2.3:a:samsung:prismview_system_9:11.10.17.00:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.017

Percentile

88.0%

Related for CVE-2019-20451