PT-2018-13424 · Opsview · Opsview Monitor

Fernando Catoira

+1

·

Publicado

2018-09-05

·

Atualizado

2019-10-03

·

CVE-2018-16146

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Opsview Monitor versions 5.4.x through 5.4.1
Description The issue affects the web management console, where an authenticated administrator can exploit a command injection flaw due to improper sanitization of the value parameter. This allows for arbitrary command execution with the privileges of the nagios user account.
Recommendations For Opsview Monitor versions 5.4.x through 5.4.1, update to version 5.4.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the web management console to minimize the risk of exploitation. Avoid using the value parameter in the affected functionality until the issue is resolved.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-16146

Produtos afetados

Opsview Monitor