TeamViewer DEX Platform On-Premises Command Injection Vulnerability
Vulnerability
A command injection vulnerability exists in TeamViewer DEX Platform On-Premises (formerly 1E DEX Platform On-Premises) versions prior to 9.2. This vulnerability arises from improper input validation, allowing authenticated users with at least questioner privileges to inject commands into specific instructions. Exploitation of this vulnerability could result in the execution of elevated commands on devices connected to the platform.
Impact
Exploitation could lead to the execution of elevated commands on connected devices.
Remediation
Users are advised to update to version 9.2 or the latest available version. TeamViewer DEX SaaS customers do not need to take any action.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
