---
cve: "CVE-2019-5644"
severity: "CRITICAL"
cvss: 10.0
epss: "1.3%"
vendor: "Computing For Good"
kev: false
exploited: false
published: "2019-11-06 19:15:12"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-06T02:45:48+02:00"
---

# CVE-2019-5644

> 10.0 CRITICAL

## Beschreibung

Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may alter several facets of a user account, including promoting any user to an administrator.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-284** — Improper Access Control
  The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

## Angriffsmuster (CAPEC)

- [CAPEC-19 — Embedding Scripts within Scripts](https://capec.mitre.org/data/definitions/19.html) _(Severity: High)_
- [CAPEC-441 — Malicious Logic Insertion](https://capec.mitre.org/data/definitions/441.html) _(Severity: High)_
- [CAPEC-478 — Modification of Windows Service Configuration](https://capec.mitre.org/data/definitions/478.html) _(Severity: High)_
- [CAPEC-479 — Malicious Root Certificate](https://capec.mitre.org/data/definitions/479.html) _(Severity: Low)_
- [CAPEC-502 — Intent Spoof](https://capec.mitre.org/data/definitions/502.html)
- [CAPEC-503 — WebView Exposure](https://capec.mitre.org/data/definitions/503.html)
- [CAPEC-536 — Data Injected During Configuration](https://capec.mitre.org/data/definitions/536.html) _(Severity: High)_
- [CAPEC-546 — Incomplete Data Deletion in a Multi-Tenant Environment](https://capec.mitre.org/data/definitions/546.html) _(Severity: Medium)_

## ATT&CK-Techniken

- [T1027.009 — Obfuscated Files or Information: Embedded Payloads](https://attack.mitre.org/techniques/T1027/009/)
- [T1546.004 — Event Triggered Execution:.bash_profile and .bashrc](https://attack.mitre.org/techniques/T1546/004/)
- [T1546.016 — Event Triggered Execution: Installer Packages](https://attack.mitre.org/techniques/T1546/016/)
- [T1574.011 — Hijack Execution Flow:Service Registry Permissions Weakness](https://attack.mitre.org/techniques/T1574/011/)
- [T1543.003 — Create or Modify System Process:Windows Service](https://attack.mitre.org/techniques/T1543/003/)
- [T1553.004 — Subvert Trust Controls:Install Root Certificate](https://attack.mitre.org/techniques/T1553/004/)

## Referenzen

- <https://blog.rapid7.com/2019/09/10/r7-2019-09-cve-2019-5617-cve-2019-5643-cve-2019-5644-c4g-blis-authentication-and-authorization-vulnerabilities-fixed/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2019-5644) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
