PT-2017-2845 · Teltonika · Teltonika Rut9Xx

Publicado

2017-04-20

·

Atualizado

2019-10-03

·

CVE-2017-8116

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Teltonika RUT9XX versions 00.03.265 and earlier
Description The issue is related to inadequate access control in the authentication request, allowing a remote attacker to execute arbitrary commands with root privileges by using shell metacharacters in the username parameter in a login request.
Recommendations For versions 00.03.265 and earlier, consider disabling the login functionality via the management interface until a patch is available. Restrict access to the management interface to minimize the risk of exploitation. Avoid using the username parameter in the affected login request until the issue is resolved.

Exploit

Correção

OS Command Injection

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02125
CVE-2017-8116

Produtos afetados

Teltonika Rut9Xx