Описание
Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' CLI access privileges to bypass a restricted shell and execute arbitrary commands as root.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.4.0.26 (исключая)
Одновременно
cpe:2.3:o:digi:transport_lr54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:digi:transport_lr54:-:*:*:*:*:*:*:*
EPSS
Процентиль: 89%
0.04506
Низкий
9.9 Critical
CVSS3
9 Critical
CVSS2
Дефекты
CWE-20
Связанные уязвимости
CVSS3: 9.9
github
больше 3 лет назад
Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' CLI access privileges to bypass a restricted shell and execute arbitrary commands as root.
EPSS
Процентиль: 89%
0.04506
Низкий
9.9 Critical
CVSS3
9 Critical
CVSS2
Дефекты
CWE-20