CVE-2019-6838
published 2019-09-17CVE-2019-6838: A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.82%
53.1th percentile
A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow a user with low privileges to delete a critical file.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | meg6260-0410_firmware | < 1.3.7 | 1.3.7 |
| schneider-electric | meg6260-0415_firmware | < 1.3.7 | 1.3.7 |
| schneider-electric | meg6501-0001_firmware | < 1.3.7 | 1.3.7 |
| schneider-electric | meg6501-0002_firmware | < 1.3.7 | 1.3.7 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4hc4-2qgx-7hp4: An Improper Access Control: CWE-284 vulnerability exists in U
ghsa_unreviewed·2022-05-24
CVE-2019-6838 [MEDIUM] GHSA-4hc4-2qgx-7hp4: An Improper Access Control: CWE-284 vulnerability exists in U
An Improper Access Control: CWE-284 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow a user with low privileges to delete a critical file.
Red Hat
audiofile: a NULL pointer dereference in ulaw2linear_buf in G711.cpp in libmodules.a leading to DoS
vendor_redhat·2019-06-30·CVSS 5.5
CVE-2019-13147 [MEDIUM] CWE-476 audiofile: a NULL pointer dereference in ulaw2linear_buf in G711.cpp in libmodules.a leading to DoS
audiofile: a NULL pointer dereference in ulaw2linear_buf in G711.cpp in libmodules.a leading to DoS
In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial of service via a crafted file.
Statement: This flaw was found to be a duplicate of CVE-2017-6838. Please see https://access.redhat.com/security/cve/CVE-2017-6838 for information about affected products and security errata.
Package: audiofile (Red Hat Enterprise Linux 5) - Not affected
Package: audiofile (Red Hat Enterprise Linux 6) - Not affected
Package: audiofile (Red Hat Enterprise Linux 7) - Not affected
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-09-17
Published