CVE-2019-18956 describes a critical remote code execution vulnerability in Divisa Proxia Suite, SparkSpace, and Proxia PHR products. This flaw stems from insecure deserialization of the "proxia-error" cookie, allowing an unauthenticated attacker to craft a malicious serialized payload. The vulnerability has a CVSS score of 9.8 (Critical), indicating it can be exploited over the network with low complexity, leading to full compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code, or significant community discussion, its high EPSS score suggests a non-trivial probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 17-62, <= 17-147CPE matchmatch criteria | cpe:2.3:a:divisait:dv2eemvc:*:*:*:*:*:*:*:* | ||
>= 18.6, < 18.6.42CPE matchmatch criteria | cpe:2.3:a:divisait:dv2eemvc:*:*:*:*:*:*:*:* | ||
>= 19.0, < 19.0.13CPE matchmatch criteria | cpe:2.3:a:divisait:dv2eemvc:*:*:*:*:*:*:*:* | ||
>= 19.1, < 19.1.19CPE matchmatch criteria | cpe:2.3:a:divisait:dv2eemvc:*:*:*:*:*:*:*:* | ||
>= 19.2, < 19.2.41CPE matchmatch criteria | cpe:2.3:a:divisait:dv2eemvc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.