Описание
The Symantec Reporter CLI 10.1 prior to 10.1.5.6 and 10.2 prior to 10.2.1.8 is susceptible to an OS command injection vulnerability. An authenticated malicious administrator with Enable mode access can execute arbitrary OS commands with elevated system privileges.
Ссылки
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 10.1 (включая) до 10.1.5.6 (исключая)Версия от 10.2 (включая) до 10.2.1.8 (исключая)
Одно из
cpe:2.3:a:symantec:reporter:*:*:*:*:*:*:*:*
cpe:2.3:a:symantec:reporter:*:*:*:*:*:*:*:*
EPSS
Процентиль: 85%
0.02444
Низкий
7.2 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-78
Связанные уязвимости
CVSS3: 7.2
github
больше 3 лет назад
The Symantec Reporter CLI 10.1 prior to 10.1.5.6 and 10.2 prior to 10.2.1.8 is susceptible to an OS command injection vulnerability. An authenticated malicious administrator with Enable mode access can execute arbitrary OS commands with elevated system privileges.
EPSS
Процентиль: 85%
0.02444
Низкий
7.2 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-78