CVE-2019-15087

HIGH

PRiSE adAS 1.7.0 - Authenticated Remote Code Execution via Password Hash Function Manipulation

Title source: llm
STIX 2.1

Description

An issue was discovered in PRiSE adAS 1.7.0. An authenticated user can change the function used to hash passwords to any function, leading to remote code execution.

References (2)

Core 2
Core References
Exploit, Patch, Third Party Advisory x_refsource_misc
https://security-garage.com/index.php/cves/from-open-redirect-to-rce-in-adas

Scores

CVSS v3 7.2
EPSS 0.0333
EPSS Percentile 87.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (1)
prise/adas 1.7.0
Published Sep 20, 2019
Tracked Since Feb 18, 2026