cvelist/2019/6xxx/CVE-2019-6546.json

62 lines
1.9 KiB
JSON
Raw Normal View History

2019-01-22 15:05:16 -05:00
{
2019-05-09 15:00:46 +00:00
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
2019-03-18 02:10:04 +00:00
"CVE_data_meta": {
"ID": "CVE-2019-6546",
2019-05-09 15:00:46 +00:00
"ASSIGNER": "ics-cert@hq.dhs.gov",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "n/a",
"product": {
"product_data": [
{
"product_name": "GE Communicator",
"version": {
"version_data": [
{
"version_value": "All versions prior to 4.0.517"
}
]
}
}
]
}
}
]
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "UNCONTROLLED SEARCH PATH CWE-427"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "MISC",
"name": "https://ics-cert.us-cert.gov/advisories/ICSA-19-122-02",
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-19-122-02"
}
]
2019-03-18 02:10:04 +00:00
},
"description": {
"description_data": [
{
"lang": "eng",
2019-05-09 15:00:46 +00:00
"value": "GE Communicator, all versions prior to 4.0.517, allows an attacker to place malicious files within the working directory of the program, which may allow an attacker to manipulate widgets and UI elements."
2019-03-18 02:10:04 +00:00
}
]
}
}