Exploit Title : eScan Management Console - Incorrect Access Control
Author : Jeyabalaji
Affected Versions : 14.0.1400.2281
Tested on : Windows 11
CVE : CVE-2024-42919
The Escan Management Console implements authentication mechanisms; however, the acteScanAVReport endpoint is accessible without requiring any authentication.
acteScanAVReport (Endpoint)
- Open eScan Management Console
- Give 'acteScanAVReport' Endpoint
- We can able to access the eScan AV Report
Update to the latest version