CVE-2023-27792
- EPSS 0.04%
- Veröffentlicht 19.10.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:53:30
An issue found in IXP Data Easy Install v.6.6.14884.0 allows an attacker to escalate privileges via lack of permissions applied to sub directories.
CVE-2023-27793
- EPSS 0.05%
- Veröffentlicht 19.10.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:53:30
An issue discovered in IXP Data Easy Install v.6.6.14884.0 allows local attackers to gain escalated privileges via weak encoding of sensitive information.
CVE-2023-27795
- EPSS 0.05%
- Veröffentlicht 19.10.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:53:30
An issue found in IXP Data Easy Install v.6.6.14884.0 allows a local attacker to gain privileges via a static XOR key.
CVE-2023-30131
- EPSS 0.24%
- Veröffentlicht 19.10.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:59:49
An issue discovered in IXP EasyInstall 6.6.14884.0 allows attackers to run arbitrary commands, gain escalated privilege, and cause other unspecified impacts via unauthenticated API calls.
CVE-2023-30132
- EPSS 0.02%
- Veröffentlicht 19.10.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:59:49
An issue discovered in IXP Data EasyInstall 6.6.14907.0 allows attackers to gain escalated privileges via static Cryptographic Key.
CVE-2023-27791
- EPSS 1.13%
- Veröffentlicht 19.10.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 07:53:29
An issue found in IXP Data Easy Install 6.6.148840 allows a remote attacker to escalate privileges via insecure PRNG.
CVE-2022-35120
- EPSS 0.03%
- Veröffentlicht 01.12.2022 22:15:10
- Zuletzt bearbeitet 24.04.2025 19:15:43
IXPdata EasyInstall 6.6.14725 contains an access control issue.
CVE-2019-19893
- EPSS 1.83%
- Veröffentlicht 23.01.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:36
In IXP EasyInstall 6.2.13723, there is Directory Traversal on TCP port 8000 via the Engine Service by an unauthenticated attacker, who can access the server's filesystem with the access rights of NT AUTHORITY\SYSTEM.
CVE-2019-19894
- EPSS 0.13%
- Veröffentlicht 23.01.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:36
In IXP EasyInstall 6.2.13723, it is possible to temporarily disable UAC by using the Agent Service on a client system. An authenticated attacker (non-admin) can disable UAC for other users by renaming and replacing %SYSTEMDRIVE%\IXP\DATA\IXPAS.IXP.
CVE-2019-19895
- EPSS 0.14%
- Veröffentlicht 23.01.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:36
In IXP EasyInstall 6.2.13723, there is Lateral Movement (using the Agent Service) against other users on a client system. An authenticated attacker can, by modifying %SYSTEMDRIVE%\IXP\SW\[PACKAGE_CODE]\EveryLogon.bat, achieve this movement and execut...