VulnerabilityModified
CVE-2018-15486
An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5.
CRITICAL 9.1EPSS 2.06%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.06%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Unauthenticated Local File Inclusion and File modification is possible through the open HTTP interface by modifying the name parameter of the file endpoint, aka KONE-02.
- CVSS 3.0
- 9.1 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 2.06% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-829
- Affected
- kone/group controller firmware
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/149252/KONE-KGC-4.6.4-DoS-Code-Execution-LFI-Bypass.htmlExploit, Third Party Advisory, VDB Entry
- https://www.kone.com/en/vulnerability.aspxVendor Advisory
- http://packetstormsecurity.com/files/149252/KONE-KGC-4.6.4-DoS-Code-Execution-LFI-Bypass.htmlExploit, Third Party Advisory, VDB Entry
- https://www.kone.com/en/vulnerability.aspxVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.