CVE-2018-15490 - CERT CVE
ID CVE-2018-15490
Sažetak An issue was discovered in ExpressVPN on Windows. The Xvpnd.exe process (which runs as a service with SYSTEM privileges) listens on TCP port 2015, which is used as an RPC interface for communication with the client side of the ExpressVPN application. A JSON-RPC protocol over HTTP is used for communication. The JSON-RPC XVPN.GetPreference and XVPN.SetPreference methods are vulnerable to path traversal, and allow reading and writing files on the file system on behalf of the service.
Reference
CVSS
Base: 6.6
Impact: 9.2
Exploitability:3.9
Pristup
VektorSloženostAutentikacija
LOCAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE COMPLETE NONE
CVSS vektor AV:L/AC:L/Au:N/C:C/I:C/A:N
Zadnje važnije ažuriranje 07-11-2023 - 02:53
Objavljeno 02-01-2019 - 18:29