RunExeFile.exe in the installer for DEWESoft X3 SP1 (64-bit) devices does not require authentication for sessions on TCP port 1999, which allows remote attackers to execute arbitrary code or access internal commands, as demonstrated by a RUN command that launches a .EXE file located at an arbitrary external URL, or a "SETFIREWALL Off" command.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T06:37:57.905Z
Reserved: 2018-03-08T00:00:00
Link: CVE-2018-7756
No data.
Status : Modified
Published: 2018-03-15T01:29:03.573
Modified: 2024-11-21T04:12:40.523
Link: CVE-2018-7756
No data.
OpenCVE Enrichment
No data.
Weaknesses