PT-2016-5100 · Meteocontrol · Meteocontrol Web'Log
Karn Ganeshen
·
Published
2016-05-14
·
Updated
2016-11-30
·
CVE-2016-2297
CVSS v2.0
9.7
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:P |
Name of the Vulnerable Software and Affected Versions
Meteocontrol WEB'log versions Basic 100, Light, Pro, and Pro Unlimited
Description
The issue allows remote attackers to execute arbitrary commands via an "access command shell-like feature."
Recommendations
For Meteocontrol WEB'log Basic 100, consider disabling the access command shell-like feature until a patch is available.
For Meteocontrol WEB'log Light, consider disabling the access command shell-like feature until a patch is available.
For Meteocontrol WEB'log Pro, consider disabling the access command shell-like feature until a patch is available.
For Meteocontrol WEB'log Pro Unlimited, consider disabling the access command shell-like feature until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Meteocontrol Web'Log