Описание
A shell command injection in the HW Events SNMP community in XoruX LPAR2RRD and STOR2RRD before 7.30 allows authenticated remote attackers to execute arbitrary shell commands as the user running the service.
Ссылки
- ExploitThird Party Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- ExploitThird Party Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.30 (исключая)Версия до 7.30 (исключая)
Одно из
cpe:2.3:a:xorux:lpar2rrd:*:*:*:*:*:*:*:*
cpe:2.3:a:xorux:stor2rrd:*:*:*:*:*:*:*:*
EPSS
Процентиль: 96%
0.23026
Средний
8.8 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-78
Связанные уязвимости
CVSS3: 8.8
github
больше 3 лет назад
A shell command injection in the HW Events SNMP community in XoruX LPAR2RRD and STOR2RRD before 7.30 allows authenticated remote attackers to execute arbitrary shell commands as the user running the service.
EPSS
Процентиль: 96%
0.23026
Средний
8.8 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-78