Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2021-36356

Disclosure Date: August 31, 2021 (last updated February 23, 2025)
KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames (even though browseSystemFiles.php is no longer reachable via the GUI). NOTE: this issue exists because of an incomplete fix for CVE-2019-17124.
Attacker Value
Unknown

CVE-2021-35064

Disclosure Date: July 12, 2021 (last updated February 23, 2025)
KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits running of multiple dangerous commands, including unzip, systemctl and dpkg.
Attacker Value
Unknown

CVE-2019-17124

Disclosure Date: October 09, 2019 (last updated November 27, 2024)
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.