vendor:
DEWESoft X3 SP1 (64-bit) installer - X3
by:
John Page (aka hyp3rlinx)
9.8
CVSS
CRITICAL
Remote Internal Command Access
N/A
CWE
Product Name: DEWESoft X3 SP1 (64-bit) installer - X3
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: CVE-2018-7756
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2018
DEWESoft X3 SP1 (64-bit) Remote Internal Command Access
The installer for DEWESoft X3 SP1 (64-bit) devices, specifically the "RunExeFile.exe" component does not require authentication for sessions on TCP port 1999, which allows remote attackers to execute arbitrary code or access internal commands, as demonstrated by a RUN command that can launch an .EXE file located at an arbitrary directory location, download an .EXE from an external URL, or Run a "SETFIREWALL Off" command.
Mitigation:
N/A