VYPR
High severity7.8NVD Advisory· Published Feb 16, 2020· Updated Jun 17, 2026

CVE-2019-20456

CVE-2019-20456

Description

Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking.

Affected products

7
  • cpe:2.3:a:goverlan:client_agent:*:*:*:*:*:*:*:*
    Range: <9.20.50
  • cpe:2.3:a:goverlan:reach_console:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:goverlan:reach_console:*:*:*:*:*:*:*:*range: <9.50
    • (no CPE)range: <9.50
  • cpe:2.3:a:goverlan:reach_server:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:goverlan:reach_server:*:*:*:*:*:*:*:*range: <3.50
    • (no CPE)range: <3.50
  • Goverlan/Goverlan Reach Consoledescription
  • Range: <9.20.50

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.