8.1
CVE-2019-6447
- EPSS 71.26%
- Veröffentlicht 16.01.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:28
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated application/json data over HTTP.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Estrongs ≫ Es File Explorer File Manager SwPlatformandroid Version <= 4.1.9.7.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 71.26% | 0.987 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
| nvd@nist.gov | 4.8 | 6.5 | 4.9 |
AV:A/AC:L/Au:N/C:P/I:P/A:N
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.