Vendor
Saltosystem
Products
1
CVEs
4
Across products
4
Status
Private
Products
1- 4 CVEs
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-19459 | Cri | 0.64 | 9.8 | 0.04 | Dec 3, 2019 | An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary… | ||
| CVE-2019-19458 | Hig | 0.56 | 8.6 | 0.03 | Dec 3, 2019 | SALTO ProAccess SPACE 5.4.3.0 allows Directory Traversal in the Data Export feature. | ||
| CVE-2019-19460 | Med | 0.36 | 5.5 | 0.00 | Dec 3, 2019 | An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local SYSTEM permissions by default. This is against the principle of least privilege. An attacker who is able to exploit CVE-2019-19458 or CVE-2019-19459 is… | ||
| CVE-2019-19457 | Med | 0.35 | 5.4 | 0.01 | Dec 3, 2019 | SALTO ProAccess SPACE 5.4.3.0 allows XSS. |
- risk 0.64cvss 9.8epss 0.04
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary…
- risk 0.56cvss 8.6epss 0.03
SALTO ProAccess SPACE 5.4.3.0 allows Directory Traversal in the Data Export feature.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local SYSTEM permissions by default. This is against the principle of least privilege. An attacker who is able to exploit CVE-2019-19458 or CVE-2019-19459 is…
- risk 0.35cvss 5.4epss 0.01
SALTO ProAccess SPACE 5.4.3.0 allows XSS.