VYPR
Low severity3.3NVD Advisory· Published Jun 18, 2020· Updated Jun 17, 2026

CVE-2019-13033

CVE-2019-13033

Description

In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed. This license can be used to upload data to a central Lynis server. Although no data can be extracted by knowing the license key, it may be possible to upload the data of additional scans.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • Cisofy/Lynis2 versions
    cpe:2.3:a:cisofy:lynis:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:cisofy:lynis:*:*:*:*:*:*:*:*range: >=2.0.0,<=2.7.5
    • (no CPE)range: 2.x - 2.7.5
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
  • CISOfy/Lynisdescription

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.