Описание
LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config and the Netcommand feature. Successful exploitation requires administrative privileges. Exploitation could result in compromise of the underlying web server.
Ссылки
- Third Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 26.3.0 (исключая)
cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 94%
0.07533
Низкий
7.2 High
CVSS3
Дефекты
CWE-78
Связанные уязвимости
github
5 месяцев назад
LibreNMS is Vulnerable to Remote Code Execution by Arbitrary File Write
EPSS
Процентиль: 94%
0.07533
Низкий
7.2 High
CVSS3
Дефекты
CWE-78