Vulnerabilities (CVE)

Filtered by vendor Ixpdata Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-19895 1 Ixpdata 1 Easyinstall 2021-07-21 4.6 MEDIUM 7.8 HIGH
In IXP EasyInstall 6.2.13723, there is Lateral Movement (using the Agent Service) against other users on a client system. An authenticated attacker can, by modifying %SYSTEMDRIVE%\IXP\SW\[PACKAGE_CODE]\EveryLogon.bat, achieve this movement and execute code in the context of other users.
CVE-2019-19898 1 Ixpdata 1 Easyinstall 2021-07-21 5.0 MEDIUM 7.5 HIGH
In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotely.
CVE-2019-19893 1 Ixpdata 1 Easyinstall 2020-01-29 7.8 HIGH 7.5 HIGH
In IXP EasyInstall 6.2.13723, there is Directory Traversal on TCP port 8000 via the Engine Service by an unauthenticated attacker, who can access the server's filesystem with the access rights of NT AUTHORITY\SYSTEM.