Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j96m-hg98-w6c4

Опубликовано: 26 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the gedtupdater service of the firmware allows remote attackers to execute arbitrary system commands with root privileges via a crafted filename parameter in POST requests to the /api/updater/ctrl/start_update endpoint.

In Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the gedtupdater service of the firmware allows remote attackers to execute arbitrary system commands with root privileges via a crafted filename parameter in POST requests to the /api/updater/ctrl/start_update endpoint.

EPSS

Процентиль: 82%
0.01658
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.8
nvd
почти 2 года назад

In Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the gedtupdater service of the firmware allows remote attackers to execute arbitrary system commands with root privileges via a crafted filename parameter in POST requests to the /api/updater/ctrl/start_update endpoint.

EPSS

Процентиль: 82%
0.01658
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77