Описание
The Device42 Remote Collector before 17.05.01 does not sanitize user input in its SNMP Connectivity utility. This allows an authenticated attacker (with access to the console application) to execute arbitrary OS commands and escalate privileges.
Ссылки
- Vendor Advisory
- ProductVendor Advisory
- Vendor Advisory
- ProductVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 17.05.01 (исключая)
cpe:2.3:a:device42:remote_collector:*:*:*:*:*:*:*:*
EPSS
Процентиль: 70%
0.00629
Низкий
8.8 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-78
Связанные уязвимости
github
больше 3 лет назад
The Device42 Remote Collector before 17.05.01 does not sanitize user input in its SNMP Connectivity utility. This allows an authenticated attacker (with access to the console application) to execute arbitrary OS commands and escalate privileges.
EPSS
Процентиль: 70%
0.00629
Низкий
8.8 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-78