Multiple vulnerabilities in AUVESY Versiondog



Published: 2021-10-20
Risk High
Patch available YES
Number of vulnerabilities 17
CVE-ID CVE-2021-38457
CVE-2021-38475
CVE-2021-38461
CVE-2021-38451
CVE-2021-38467
CVE-2021-38479
CVE-2021-38449
CVE-2021-38473
CVE-2021-38471
CVE-2021-38477
CVE-2021-38453
CVE-2021-38455
CVE-2021-38463
CVE-2021-38469
CVE-2021-38459
CVE-2021-38481
CVE-2021-38465
CWE-ID CWE-284
CWE-732
CWE-321
CWE-125
CWE-416
CWE-787
CWE-123
CWE-119
CWE-434
CWE-73
CWE-20
CWE-400
CWE-427
CWE-294
CWE-89
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
Versiondog
Other software / Other software solutions

Vendor AUVESY

Security Bulletin

This security bulletin contains information about 17 vulnerabilities.

1) Improper access control

EUVDB-ID: #VU57557

Risk: High

CVSSv3.1: 7.9 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-38457

CWE-ID: CWE-284 - Improper Access Control

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. A remote attacker can initiate a session with the server without providing any form of authentication.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Versiondog: 5.0.0, 5.5.0, 6.0.0, 6.5.0, 7.0.0, 7.5.0

CPE2.3 External links

http://ics-cert.us-cert.gov/advisories/icsa-21-292-01

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Incorrect permission assignment for critical resource

EUVDB-ID: #VU57558

Risk: Medium

CVSSv3.1: 6.4 [CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-38475

CWE-ID: CWE-732 - Incorrect Permission Assignment for Critical Resource

Exploit availability: No

Description

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to the database connection to the server is performed by calling a specific API. A remote authenticated attacker can gain SYSDBA permissions.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Versiondog: 5.0.0, 5.5.0, 6.0.0, 6.5.0, 7.0.0, 7.5.0

CPE2.3 External links

http://ics-cert.us-cert.gov/advisories/icsa-21-292-01

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Use of Hard-coded Cryptographic Key

EUVDB-ID: #VU57559

Risk: High

CVSSv3.1: 7.1 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-38461

CWE-ID: CWE-321 - Use of Hard-coded Cryptographic Key

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the affected product uses a hard-coded blowfish key for encryption/decryption processes. A remote attacker can extract the key from binaries.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Versiondog: 5.0.0, 5.5.0, 6.0.0, 6.5.0, 7.0.0, 7.5.0

CPE2.3 External links

http://ics-cert.us-cert.gov/advisories/icsa-21-292-01

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Out-of-bounds read

EUVDB-ID: #VU57560

Risk: Medium

CVSSv3.1: 4.2 [CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-38451

CWE-ID: CWE-125 - Out-of-bounds Read

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition. A remote authenticated attacker can trigger out-of-bounds read error and read contents of memory on the system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Versiondog: 5.0.0, 5.5.0, 6.0.0, 6.5.0, 7.0.0, 7.5.0

CPE2.3 External links

http://ics-cert.us-cert.gov/advisories/icsa-21-292-01

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

5) Use-after-free

EUVDB-ID: #VU57561

Risk: High

CVSSv3.1: 7.1 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-38467

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error. A remote attacker can control what memory regions will be freed and cause use-after-free condition.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Versiondog: 5.0.0, 5.5.0, 6.0.0, 6.5.0, 7.0.0, 7.5.0

CPE2.3 External links

http://ics-cert.us-cert.gov/advisories/icsa-21-292-01

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

6) Out-of-bounds write

EUVDB-ID: #VU57562

Risk: High

CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-38479

CWE-ID: CWE-787 - Out-of-bounds Write

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input within many API function codes. A remote attacker can trigger out-of-bounds write and execute arbitrary code on the target system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Versiondog: 5.0.0, 5.5.0, 6.0.0, 6.5.0, 7.0.0, 7.5.0

CPE2.3 External links

http://ics-cert.us-cert.gov/advisories/icsa-21-292-01

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

7) Write-what-where Condition

EUVDB-ID: #VU57563

Risk: High

CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-38449

CWE-ID: CWE-123 - Write-what-where Condition

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to a write-what-where condition. A remote attacker can rewrite the memory in any location of the affected product.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Versiondog: 5.0.0, 5.5.0, 6.0.0, 6.5.0, 7.0.0, 7.5.0

CPE2.3 External links

http://ics-cert.us-cert.gov/advisories/icsa-21-292-01

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

8) Buffer overflow

EUVDB-ID: #VU57564

Risk: Medium

CVSSv3.1: 7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-38473

CWE-ID: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing Microsoft Office files. A remote authenticated attacker can trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Versiondog: 5.0.0, 5.5.0, 6.0.0, 6.5.0, 7.0.0, 7.5.0

CPE2.3 External links

http://ics-cert.us-cert.gov/advisories/icsa-21-292-01

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

9) Arbitrary file upload

EUVDB-ID: #VU57565

Risk: High

CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-38471

CWE-ID: CWE-434 - Unrestricted Upload of File with Dangerous Type

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to insufficient validation of file during file upload within multiple API function. A remote attacker can upload a malicious file and execute it on the server.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Versiondog: 5.0.0, 5.5.0, 6.0.0, 6.5.0, 7.0.0, 7.5.0

CPE2.3 External links

http://ics-cert.us-cert.gov/advisories/icsa-21-292-01

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

10) External Control of File Name or Path

EUVDB-ID: #VU57566

Risk: High

CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-38477

CWE-ID: CWE-73 - External Control of File Name or Path

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the multiple API function codes permit reading and writing data to or from files and directories. A remote attacker can manipulate and/or delete arbitrary files on the target system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Versiondog: 5.0.0, 5.5.0, 6.0.0, 6.5.0, 7.0.0, 7.5.0

CPE2.3 External links

http://ics-cert.us-cert.gov/advisories/icsa-21-292-01

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

11) Input validation error

EUVDB-ID: #VU57567

Risk: High

CVSSv3.1: 7.9 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-38453

CWE-ID: CWE-20 - Improper Input Validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to some API functions allow interaction with the registry. A remote attacker can read values and modificate the data.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Versiondog: 5.0.0, 5.5.0, 6.0.0, 6.5.0, 7.0.0, 7.5.0

CPE2.3 External links

http://ics-cert.us-cert.gov/advisories/icsa-21-292-01

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

12) Input validation error

EUVDB-ID: #VU57568

Risk: Medium

CVSSv3.1: 6.4 [CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-38455

CWE-ID: CWE-20 - Improper Input Validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the affected product’s OS Service does not verify any given parameter. A remote authenticated attacker can supply any type of parameter that will be passed to inner calls without checking the type of the parameter or the value.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Versiondog: 5.0.0, 5.5.0, 6.0.0, 6.5.0, 7.0.0, 7.5.0

CPE2.3 External links

http://ics-cert.us-cert.gov/advisories/icsa-21-292-01

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

13) Resource exhaustion

EUVDB-ID: #VU57569

Risk: Medium

CVSSv3.1: 5 [CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-38463

CWE-ID: CWE-400 - Uncontrolled Resource Consumption ('Resource Exhaustion')

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote authenticated attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Versiondog: 5.0.0, 5.5.0, 6.0.0, 6.5.0, 7.0.0, 7.5.0

CPE2.3 External links

http://ics-cert.us-cert.gov/advisories/icsa-21-292-01

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

14) Insecure DLL loading

EUVDB-ID: #VU57570

Risk: High

CVSSv3.1: 7.9 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-38469

CWE-ID: CWE-427 - Uncontrolled Search Path Element

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to the application loads DLL libraries in an insecure manner. A remote attacker can implant their own DLL near the affected product’s binaries and hijack the loaded DLL.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Versiondog: 5.0.0, 5.5.0, 6.0.0, 6.5.0, 7.0.0, 7.5.0

CPE2.3 External links

http://ics-cert.us-cert.gov/advisories/icsa-21-292-01

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

15) Authentication Bypass by Capture-replay

EUVDB-ID: #VU57571

Risk: High

CVSSv3.1: 7.1 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-38459

CWE-ID: CWE-294 - Authentication Bypass by Capture-replay

Exploit availability: No

Description

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to the data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level. A remote attacker can bypass authentication process and change user passwords or delete the database.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Versiondog: 5.0.0, 5.5.0, 6.0.0, 6.5.0, 7.0.0, 7.5.0

CPE2.3 External links

http://ics-cert.us-cert.gov/advisories/icsa-21-292-01

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

16) SQL injection

EUVDB-ID: #VU57572

Risk: Medium

CVSSv3.1: 6.2 [CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-38481

CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.

The vulnerability exists due to insufficient sanitization of user-supplied data within JOB ID. A remote authenticated attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.

Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Versiondog: 5.0.0, 5.5.0, 6.0.0, 6.5.0, 7.0.0, 7.5.0

CPE2.3 External links

http://ics-cert.us-cert.gov/advisories/icsa-21-292-01

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

17) Resource exhaustion

EUVDB-ID: #VU57573

Risk: Medium

CVSSv3.1: 7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-38465

CWE-ID: CWE-400 - Uncontrolled Resource Consumption ('Resource Exhaustion')

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote authenticated attacker can trigger resource exhaustion and execute arbitrary code on the target system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Versiondog: 5.0.0, 5.5.0, 6.0.0, 6.5.0, 7.0.0, 7.5.0

CPE2.3 External links

http://ics-cert.us-cert.gov/advisories/icsa-21-292-01

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###