Directory Traversal Vulnerability in Naver Vaccine Software
CVE-2019-13157

7.5HIGH

Key Information:

Vendor
CVE Published:
22 November 2019

What is CVE-2019-13157?

The nsGreen.dll component in Naver Vaccine version 2.1.4 is prone to a directory traversal vulnerability that enables remote attackers to manipulate and overwrite arbitrary files by leveraging crafted filename sequences within nsz archives. This flaw can potentially compromise the integrity of the system, making it critical for users to apply necessary security updates and mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Naver Vaccine <= 2.1.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

JAEWOOK SHIN(powerprove, null2root, proveofhack@gmail.com) and JINWOO PARK (P4rkJW, CAT-Security)
.