PT-2017-19318 · Green Packet · Green Packet Dx-350

Published

2017-07-21

·

Updated

2020-12-31

·

CVE-2017-9980

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb
Description The issue concerns command injection via the pip parameter in the PING feature, also known as tag ipPing, within the web interface.
Recommendations For Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, as a temporary workaround, consider disabling the PING feature until a patch is available. Avoid using the pip parameter in the affected web interface until the issue is resolved.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-9980

Affected Products

Green Packet Dx-350