PT-2019-14226 · Vera · Vera Edge Home Controller
Publicado
2019-08-23
·
Atualizado
2020-08-24
·
CVE-2019-15498
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Vera Edge Home Controller version 1.7.4452
Description
The issue allows remote unauthenticated users to execute arbitrary OS commands. This is achieved through argument injection in the
username parameter to the "/cgi-bin/cmh/webcam.sh" API endpoint.Recommendations
For Vera Edge Home Controller version 1.7.4452, avoid using the
username parameter in the "/cgi-bin/cmh/webcam.sh" API endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the "/cgi-bin/cmh/webcam.sh" endpoint to minimize the risk of exploitation.Exploit
Correção
Argument Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Vera Edge Home Controller