MOTEX Lanscope Endpoint Manager Client program
cpe:2.3:a:motex:lanscope_cat_client_program:*:*:*:*:*:*:*
- <= 9.4.7.1
This vulnerability is being actively exploited in the wild.
A vulnerability allowing arbitrary code execution has been identified in Lanscope Endpoint Manager (On-Premises) versions through 9.4.7.1. This issue arises in the client program (MR) and detection agent (DA) due to improper verification of the source of incoming requests, enabling attackers to execute code by sending specially crafted packets.
Exploitation of this vulnerability allows for arbitrary code execution on the affected system.
Users are advised to update Lanscope Endpoint Manager (On-Premises) to the latest version. The update process is the same as the usual version upgrade. For more details, refer to the information available on the Lanscope Portal, accessible with an ID and password.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.