|
|||
Rule General Information |
---|
Release Date: | 2022-09-19 | |
Rule Name: | ES File Explorer File Manager Policy Bypass Vulnerability (CVE-2019-6447) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated application/json data over HTTP. | |
Impact: | An attacker can take advantage of the vulnerability to bypass the security policy implemented by the software administrator, and perform unauthorized actions to the target system. | |
Affected OS: | Windows, Linux, Others | |
Reference: | http://packetstormsecurity.com/files/163303/ES-File-Explorer-4.1.9.7.4-Arbitrary-File-Read.html https://github.com/fs0c131y/ESFileExplorerOpenPortVuln https://twitter.com/fs0c131y/status/1085460755313508352 |
|
Solutions |
---|
The vendor has released upgrade patches to fix vulnerabilities, please visit: http://www.estrongs.com/ |