Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-25029

Опубликовано: 26 мая 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsafe user supplied data (forms, cookies, HTTP headers etc.) to a system shell. In this attack, the attacker-supplied operating system commands are usually executed with the privileges of the vulnerable application. Command injection attacks are possible largely due to insufficient input validation.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:versa-networks:versa_director:-:*:*:*:*:*:*:*

EPSS

Процентиль: 85%
0.02411
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-77
CWE-77

Связанные уязвимости

github
больше 3 лет назад

In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsafe user supplied data (forms, cookies, HTTP headers etc.) to a system shell. In this attack, the attacker-supplied operating system commands are usually executed with the privileges of the vulnerable application. Command injection attacks are possible largely due to insufficient input validation.

EPSS

Процентиль: 85%
0.02411
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-77
CWE-77