Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local SYSTEM permissions by default. This is against the principle of least privilege. An attacker who is able to exploit CVE-2019-19458 or CVE-2019-19459 is basically able to write to every single path on the file system, because the webserver is running with the highest privileges available.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Salto Systems ProAccess SPACE 安全漏洞
Vulnerability Description
Salto Systems ProAccess SPACE是西班牙Salto Systems公司的一套基于Web的门禁访问控制管理工具。 Salto Systems ProAccess SPACE 5.4.3.0版本中存在安全漏洞。攻击者可利用该漏洞向文件系统上的任意路径进行写入操作。
CVSS Information
N/A
Vulnerability Type
N/A