CVE-2019-20451 describes a critical remote code execution vulnerability affecting Prismview System 9 and Prismview Player 11, allowing an attacker to upload malicious files and trigger system reboots or VNC restarts. This vulnerability carries a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability, despite requiring authentication which can be bypassed by downloading an XML file with credentials. While the EPSS score indicates a higher-than-average exploitability probability, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
13.09.1100CPE matchmatch criteria | cpe:2.3:a:samsung:prismview_player_11:13.09.1100:*:*:*:*:*:*:* | ||
11.10.17.00CPE matchmatch criteria | cpe:2.3:a:samsung:prismview_system_9:11.10.17.00:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.