PT-2014-8505 · Advantech · Advantech Eki-6340
Publicado
2014-11-20
·
Atualizado
2018-10-09
·
CVE-2014-8387
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Advantech EKI-6340 version 2.05
Description
The issue allows remote authenticated users to execute arbitrary commands via shell metacharacters in the
pinghost parameter to "ping.cgi" API endpoint.Recommendations
For Advantech EKI-6340 version 2.05, avoid using the
pinghost parameter in the "ping.cgi" API endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the "ping.cgi" endpoint to minimize the risk of exploitation.Exploit
Correção
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Advantech Eki-6340