Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-6079

Опубликовано: 16 мая 2017
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Средний

Описание

The HTTP web-management application on Edgewater Networks Edgemarc appliances has a hidden page that allows for user-defined commands such as specific iptables routes, etc., to be set. You can use this page as a web shell essentially to execute commands, though you get no feedback client-side from the web application: if the command is valid, it executes. An example is the wget command. The page that allows this has been confirmed in firmware as old as 2006.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:ribboncommunications:edgemarc_firmware:-:*:*:*:*:*:*:*

Одно из

cpe:2.3:h:ribboncommunications:edgemarc_4550:-:*:*:*:*:*:*:*
cpe:2.3:h:ribboncommunications:edgemarc_4552:-:*:*:*:*:*:*:*
cpe:2.3:h:ribboncommunications:edgemarc_4601:-:*:*:*:*:*:*:*
cpe:2.3:h:ribboncommunications:edgemarc_4700:-:*:*:*:*:*:*:*
cpe:2.3:h:ribboncommunications:edgemarc_4750:-:*:*:*:*:*:*:*
cpe:2.3:h:ribboncommunications:edgemarc_4800:-:*:*:*:*:*:*:*
cpe:2.3:h:ribboncommunications:edgemarc_4806:-:*:*:*:*:*:*:*
cpe:2.3:h:ribboncommunications:edgemarc_4808:-:*:*:*:*:*:*:*
cpe:2.3:h:ribboncommunications:edgemarc_7301:-:*:*:*:*:*:*:*
cpe:2.3:h:ribboncommunications:edgemarc_7400:-:*:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.3236
Средний

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

The HTTP web-management application on Edgewater Networks Edgemarc appliances has a hidden page that allows for user-defined commands such as specific iptables routes, etc., to be set. You can use this page as a web shell essentially to execute commands, though you get no feedback client-side from the web application: if the command is valid, it executes. An example is the wget command. The page that allows this has been confirmed in firmware as old as 2006.

CVSS3: 9.8
fstec
почти 9 лет назад

Уязвимость компонента HTTP Web-Management программного обеспечения устройств Edgewater Networks Edgemarc, позволяющая нарушителю выполнить произвольную команду

EPSS

Процентиль: 97%
0.3236
Средний

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

NVD-CWE-noinfo