PT-2019-15850 · Zmanda · Zmanda Management Console
Robertchrk
·
Publicado
2019-12-01
·
Atualizado
2020-08-24
·
CVE-2019-19469
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zmanda Management Console version 3.3.9
Description
The issue allows for CSRF, as demonstrated by command injection with shell metacharacters, potentially due to weak default credentials. This can be exploited through the "ZMC Admin Advanced?form=adminTasks&action=Apply&command=" API endpoint.
Recommendations
For Zmanda Management Console version 3.3.9, consider disabling the
ZMC Admin Advanced function or restricting access to the "ZMC Admin Advanced?form=adminTasks&action=Apply&command=" endpoint until a patch is available. Additionally, changing default credentials to stronger ones may help mitigate the risk.Exploit
Correção
CSRF
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Zmanda Management Console