Unknown · Wfilter Icf · CVE-2021-3243
Name of the Vulnerable Software and Affected Versions:
Wfilter ICF version 5.0.117
Description:
The issue allows an attacker in the same LAN to inject a payload into the system's logs by crafting a packet with a malicious `User-Agent` header. This can lead to a takeover of the system through its plugin-running function.
Recommendations:
For Wfilter ICF version 5.0.117, consider disabling the plugin-running function as a temporary workaround until a patch is available. Restrict access to the system's logs to minimize the risk of exploitation.