PT-2018-1517 · Phoenix Contact · Fl Switch 3Xxx+2

Vyacheslav Moskvin

·

Publicado

2018-02-22

·

Atualizado

2018-06-19

·

CVE-2018-10730

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products versions 1.0 through 1.33
Description The issue is related to OS command injection due to the lack of neutralization of special elements in OS command inputs. This can allow a remote attacker to execute arbitrary commands. The vulnerability is associated with the config transfer.cgi and software update.cgi components of the firmware.
Recommendations For versions 1.0 through 1.33, consider disabling the config transfer.cgi and software update.cgi components as a temporary workaround until a patch is available. Restrict access to these components to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-01072
CVE-2018-10730

Produtos afetados

Fl Switch 3Xxx
Fl Switch 48Xx
Fl Switch 4Xxx