← back
CVE-2019-18283CWE-502

CVE-2019-18283

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 5.4%
exploitation probability
5.4%top 8% of all CVEs
observed exploitation
nono source reports it
In short

The SPPA-T3000 Application Server allows anyone with network access to send malicious data to an unprotected service, which can execute arbitrary code on the server. This is dangerous because attackers can take full control of the system.

Technical detail

CWE-502 (Deserialization of Untrusted Data) vulnerability in AdminService of SPPA-T3000 versions prior to R8.2 SP2. The service accepts unauthenticated remote objects and deserializes them without validation, enabling remote code execution. Exploitation requires network access to the Application Highway.

Summary generated and translated by AI from the official description.
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacker can gain remote code execution by sending specifically crafted objects to one of its functions. Please note that an attacker needs to have access to the Application Highway in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.