AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-11029

HIGH · CVSS 7.5 EPSS 2.49%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-08-22 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-11029
Severity
HIGH
CVSS
7.5
EPSS
2.49%

Original NVD Description

Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Download() method of AutoUpdateService in SMServer.exe, leading to Directory Traversal. An attacker could use ..\ with this method to iterate over lists of interesting system files and download them without previous authentication. This includes SAM-database backups, Web.config files, etc. and might cause a serious impact on confidentiality.