Описание
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise.
Уязвимые конфигурации
Конфигурация 1Версия до 7.2.63.3 (исключая)Версия до 7.2.63.3 (исключая)Версия до 7.2.63.3 (исключая)Версия до 7.2.54.19 (исключая)Версия от 7.2.55.0 (включая) до 7.2.63.3 (исключая)
Одно из
cpe:2.3:a:progress:connection_manager_for_objectscale:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:moveit_web_application_firewall:*:*:*:*:*:*:*:*
cpe:2.3:o:progress:loadmaster:*:*:*:*:*:*:*:*
cpe:2.3:o:progress:loadmaster:*:*:*:*:*:*:*:*
EPSS
Процентиль: 71%
0.01414
Низкий
8.4 High
CVSS3
Дефекты
CWE-78
Связанные уязвимости
CVSS3: 8.4
github
около 1 месяца назад
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise.
EPSS
Процентиль: 71%
0.01414
Низкий
8.4 High
CVSS3
Дефекты
CWE-78