Remote Code Execution via Unauthenticated Configuration File Upload in AssetView

Remote Code Execution via Unauthenticated Configuration File Upload in AssetView

CVE-2022-28719 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the system configuration to upload a crafted configuration file to the managing server, which may result in the managed clients to execute arbitrary code with the administrative privilege.

Learn more about our Cis Benchmark Audit For Server Software.