5.3

CVE-2019-7312

Limited plaintext disclosure exists in PRIMX Zed Entreprise for Windows before 6.1.2240, Zed Entreprise for Windows (ANSSI qualification submission) before 6.1.2150, Zed Entreprise for Mac before 2.0.199, Zed Entreprise for Linux before 2.0.199, Zed Pro for Windows before 1.0.195, Zed Pro for Mac before 1.0.199, Zed Pro for Linux before 1.0.199, Zed Free for Windows before 1.0.195, Zed Free for Mac before 1.0.199, and Zed Free for Linux before 1.0.199. Analyzing a Zed container can lead to the disclosure of plaintext content of very small files (a few bytes) stored into it.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Primx ≫ Zed SwEdition free SwPlatform windows Version < 1.0.195
Primx ≫ Zed SwEdition pro SwPlatform windows Version < 1.0.195
Primx ≫ Zed SwEdition free SwPlatform linux Version < 1.0.199
Primx ≫ Zed SwEdition free SwPlatform mac Version < 1.0.199
Primx ≫ Zed SwEdition pro SwPlatform linux Version < 1.0.199
Primx ≫ Zed SwEdition pro SwPlatform mac Version < 1.0.199
Primx ≫ Zed SwEdition entreprise SwPlatform linux Version < 2.0.199
Primx ≫ Zed SwEdition entreprise SwPlatform mac Version < 2.0.199
Primx ≫ Zed SwEdition entreprise SwPlatform windows Version < 6.1.2240
Primx ≫ Zedmail SwPlatform windows Version < 6.1.2240
Primx ≫ Zonecentral SwPlatform windows Version < 6.1.2240
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.1% 0.614
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://www.primx.eu/en/bulletins/security-bulletin-19110545
Third Party Advisory