Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-27224

Опубликовано: 09 мая 2022
Источник: nvd
CVSS3: 7.2
CVSS2: 9
EPSS Средний

Описание

An issue was discovered in Galleon NTS-6002-GPS 4.14.103-Galleon-NTS-6002.V12 4. An authenticated attacker can perform command injection as root via shell metacharacters within the Network Tools section of the web-management interface. All three networking tools are affected (Ping, Traceroute, and DNS Lookup) and their respective input fields (ping_address, trace_address, nslookup_address).

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:galsys:nts-6002-gps_firmware:4.14.103-galleon-nts-6002.v12_4:*:*:*:*:*:*:*
cpe:2.3:h:galsys:nts-6002-gps:-:*:*:*:*:*:*:*

EPSS

Процентиль: 94%
0.13416
Средний

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

An issue was discovered in Galleon NTS-6002-GPS 4.14.103-Galleon-NTS-6002.V12 4. An authenticated attacker can perform command injection as root via shell metacharacters within the Network Tools section of the web-management interface. All three networking tools are affected (Ping, Traceroute, and DNS Lookup) and their respective input fields (ping_address, trace_address, nslookup_address).

EPSS

Процентиль: 94%
0.13416
Средний

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78