Senstar · Senstar Symphony · CVE-2020-17405
Name of the Vulnerable Software and Affected Versions:
Senstar Symphony version 7.3.2.2
Description:
This issue allows network-adjacent attackers to execute arbitrary code on affected installations. Authentication is not required to exploit this issue. The specific flaw exists within the `SSOAuth` process, resulting from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this issue to execute code in the context of `SYSTEM`.
Recommendations:
For Senstar Symphony version 7.3.2.2, consider disabling the `SSOAuth` process as a temporary workaround until a patch is available. Restrict access to the `SSOAuth` process to minimize the risk of exploitation. Avoid using untrusted data in the deserialization process until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.