VulnerabilityModified
CVE-2019-17445
The agent executable, when installed for non-root operations (scanning), can be forced to copy files from the filesystem to other locations via Symbolic Link Following.
MEDIUM 5.5EPSS 0.34%
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be forced to copy files from the filesystem to other locations via Symbolic Link Following.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.34% probability · 27th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-59
- Affected
- eracent/eda agent · eracent/epa agent · eracent/epm agent · eracent/eua agent · eracent/flw agent · eracent/sum agent
- Source
- cve@mitre.org
References
- https://eracent.com/security-bulletin-cve-2019-17445/Vendor Advisory
- https://eracent.com/security-bulletin-cve-2019-17445/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.