PT-2017-19318 · Green Packet · Green Packet Dx-350
Published
2017-07-21
·
Updated
2020-12-31
·
CVE-2017-9980
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb
Description
The issue concerns command injection via the
pip parameter in the PING feature, also known as tag ipPing, within the web interface.Recommendations
For Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, as a temporary workaround, consider disabling the
PING feature until a patch is available. Avoid using the pip parameter in the affected web interface until the issue is resolved.Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Green Packet Dx-350