S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2019-17503 Scanner

CVE-2019-17503 scanner - Information Disclosure vulnerability in Kirona Dynamic Resource Scheduling (DRS)

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-17503
5.3
CVSS

An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REGISTER.cmd (aka /osm_tiles/REGISTER.cmd) directly: it contains sensitive information about the database through the SQL queries within this batch file. This file exposes SQL database information such as database version, table name, column name, etc.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Kirona Dynamic Resource Scheduling (DRS) is a scheduling software that is used for resource optimization in various industries. Primarily, it is designed for organizations that offer maintenance or mobile services, as it helps to efficiently allocate resources, minimize travel time and costs, and improve customer satisfaction. The software allows for real-time scheduling and rescheduling based on changes in availability, skills, and job prioritization. In addition, it offers an integrated view of asset performance data and workflow automation capabilities.

One of the vulnerabilities detected in Kirona DRS is CVE-2019-17503. This vulnerability allows for unauthenticated users to access sensitive information in the /osm/REGISTER.cmd file. This file contains SQL queries that reveal important details about the database used by Kirona DRS, including its version, table name, and column name. Exploiting this vulnerability can give malicious actors access to sensitive data, including customer information, service schedules, and other confidential information.

If this vulnerability is exploited, it can lead to severe consequences for the affected organization. The sensitive data obtained by the attackers can be used for identity theft, fraud, or to compromise the organization's ability to provide efficient and effective services. In addition, the unauthorized access can result in legal, financial, and reputational damages.

It is important to note that security is an ongoing process, and organizations should continuously review and update their security measures to ensure the protection of their digital assets. At s4e.io, we offer pro features that can help digital asset owners easily and quickly learn about vulnerabilities affecting their systems. Our platform provides comprehensive vulnerability scans, security ratings, and threat intelligence to help organizations stay ahead of the curve. Together, we can make the digital world a more secure place.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Apply the latest security patches offered by Kirona to address this vulnerability.
  • Limit access to the /osm/REGISTER.cmd file by only allowing authenticated users to access it.
  • Ensure that sensitive data is encrypted or stored in secure databases separate from the Kirona DRS database.
  • Implement multifactor authentication to enhance security.
  • Regularly monitor and audit access to the software.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-17503 scanner - Information Disclosure vulnerability in Kirona Dynamic Resource Scheduling (DRS) | S4E