CVE-2019-15119 is a file permission vulnerability affecting cnlh nps versions up to 0.23.2, where the installer sets overly permissive 0777 permissions for the nps executable in /usr/local/bin or /usr/bin. This allows a local user to overwrite the nps executable, potentially leading to unauthorized code execution. The vulnerability has a CVSS score of 5.5 (Medium) with a local attack vector and low attack complexity, but requires user interaction. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.23.2CPE matchmatch criteria | cpe:2.3:a:ehang-io:nps:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.