Описание
The test connection functionality in the NetAudit section of Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to command injection due to improper sanitization of the rancid_password parameter.
Ссылки
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- ExploitMailing ListThird Party Advisory
- ExploitThird Party Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- ExploitMailing ListThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.3.1 (исключая)Версия от 5.4.0 (включая) до 5.4.2 (исключая)
Одно из
cpe:2.3:a:opsview:opsview:*:*:*:*:*:*:*:*
cpe:2.3:a:opsview:opsview:*:*:*:*:*:*:*:*
EPSS
Процентиль: 96%
0.23981
Средний
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-78
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
The test connection functionality in the NetAudit section of Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to command injection due to improper sanitization of the rancid_password parameter.
EPSS
Процентиль: 96%
0.23981
Средний
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-78