vendor:
Movicon
by:
Jeremy Brown
7.5
CVSS
HIGH
Remote Code Execution
284
CWE
Product Name: Movicon
Affected Version From: Progea Movicon 11
Affected Version To: Progea Movicon 11
Patch Exists: YES
Related CWE: N/A
CPE: a:progea:movicon:11
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2011
Progea Movicon TCPUploadServer Remote Exploit
TCPUploadServer allows remote users to execute functions on the server without any form of authentication. Impacts include deletion of arbitrary files, execution of a program with an arbitrary argument, crashing the server, information disclosure, and more. This design flaw puts the host running this server at risk of potentially unauthorized functions being executed on the system.
Mitigation:
Update to the latest version of Progea Movicon 11 TCPUploadServer