VulnerabilityModified
CVE-2019-15719
Altair PBS Professional through 19.1.2 allows Privilege Escalation because an attacker can send a message directly to pbs_mom, which fails to properly authenticate the message.
HIGH 8.0EPSS 1.97%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.97%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Altair PBS Professional through 19.1.2 allows Privilege Escalation because an attacker can send a message directly to pbs_mom, which fails to properly authenticate the message. This results in code execution as an arbitrary user.
- CVSS 3.1
- 8.0 HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.97% probability · 79th percentile
- CISA KEV
- Not listed
- Affected
- altair/pbs professional
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/154782/PBS-Professional-19.2.3-Authentication-Bypass.htmlExploit, Third Party Advisory, VDB Entry
- https://www.hpcsec.comThird Party Advisory
- https://www.hpcsec.com/2019/10/08/cve-2019-15719/Exploit, Third Party Advisory
- https://www.pbspro.org/Product
- http://packetstormsecurity.com/files/154782/PBS-Professional-19.2.3-Authentication-Bypass.htmlExploit, Third Party Advisory, VDB Entry
- https://www.hpcsec.comThird Party Advisory
- https://www.hpcsec.com/2019/10/08/cve-2019-15719/Exploit, Third Party Advisory
- https://www.pbspro.org/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.