Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the "Object Marshalling" technique, which allows an attacker to read internal files without any authentication. This is possible by crafting specific .NET Remoting URLs derived from information enumerated in the client-side configuration files. This issue affects IntelliSpace Portal: 12 and prior.

CVSS 1 Total

ScoreSeverityVersionVector String
7.7HIGH4.0CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/S:P/AU:Y/R:U/V:C/RE:M/U:Green

Product Status

Learn more

Versions 1 Total

Default Status: unaffected

affected

Credits

  • Victor A Morales finder
  • Omar A Crespo finder

Authorized Data Publishers