← Back to CVEs
CVE-2018-5198
HIGH8.1
Description
In Veraport G3 ALL on MacOS, a race condition when calling the Veraport API allow remote attacker to cause arbitrary file download and execution. This results in remote code execution.
CVE Details
CVSS v3.1 Score8.1
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
Published12/20/2018
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
wizvera:veraport_g3
Weaknesses (CWE)
CWE-362
References
https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=30112(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.