PT-2017-3431 · Cohu · Cohu 3960Hd

Jeremy Johnson

·

Published

2017-11-22

·

Updated

2017-12-12

·

CVE-2017-8862

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cohu 3960HD (affected versions not specified)
Description The issue concerns the webupgrade function, which does not properly verify firmware upgrade files or the upgrade process. This allows an attacker to upload a specially crafted postinstall.sh file that will be executed with root privileges. The vulnerability is related to unrestricted file upload of dangerous types, enabling a remote attacker to execute arbitrary code with root privileges by uploading a specially formed archive containing the postinstall.sh file.
Recommendations As a temporary workaround, consider disabling the webupgrade function until a patch is available. Restrict access to the Cohu 3960HD to minimize the risk of exploitation. Avoid using the webupgrade function to upload firmware until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00219
CVE-2017-8862

Affected Products

Cohu 3960Hd