Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-9507

Опубликовано: 30 мар. 2020
Источник: nvd
CVSS3: 8.3
CVSS3: 7.2
CVSS2: 9
EPSS Низкий

Описание

The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to command injection because the application incorrectly neutralizes code syntax before executing. Since all commands within the web application are executed as root, this could allow a remote attacker authenticated with an administrator account to execute arbitrary commands as root.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:vertiv:avocent_umg-4000_firmware:4.2.1.19:*:*:*:*:*:*:*
cpe:2.3:h:vertiv:avocent_umg-4000:-:*:*:*:*:*:*:*

EPSS

Процентиль: 71%
0.00692
Низкий

8.3 High

CVSS3

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-95
CWE-77

Связанные уязвимости

github
больше 3 лет назад

The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to command injection because the application incorrectly neutralizes code syntax before executing. Since all commands within the web application are executed as root, this could allow a remote attacker authenticated with an administrator account to execute arbitrary commands as root.

EPSS

Процентиль: 71%
0.00692
Низкий

8.3 High

CVSS3

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-95
CWE-77