CVE-2019-6546
HIGHGE Communicator < 4.0.517 - Uncontrolled Search Path
Title source: ruleDescription
GE Communicator, all versions prior to 4.0.517, allows an attacker to place malicious files within the working directory of the program, which may allow an attacker to manipulate widgets and UI elements.
Scores
CVSS v3
7.8
EPSS
0.0015
EPSS Percentile
36.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-427
Status
published
Affected Products (1)
ge/ge_communicator
< 4.0.517
Timeline
Published
May 09, 2019
Tracked Since
Feb 18, 2026