CVE detail
CVE-2019-19585 — CVE-2019-19585
Published 2020-01-06 · Modified 2026-06-17 · Vendor rconfig · Product rconfig · Source nvd
HIGH
severity
CVSS-derived band
0.0574
EPSS probability
exploitation probability, 30d
92.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An issue was discovered in rConfig 3.9.3. The install script updates the /etc/sudoers file for rconfig specific tasks. After an "rConfig specific Apache configuration" update, apache has high privileges for some binaries. This can be exploited by an attacker to bypass local security restrictions.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References