PT-2017-3431 · Cohu · Cohu 3960Hd
Jeremy Johnson
·
Published
2017-11-22
·
Updated
2017-12-12
·
CVE-2017-8862
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cohu 3960HD (affected versions not specified)
Description
The issue concerns the webupgrade function, which does not properly verify firmware upgrade files or the upgrade process. This allows an attacker to upload a specially crafted postinstall.sh file that will be executed with root privileges. The vulnerability is related to unrestricted file upload of dangerous types, enabling a remote attacker to execute arbitrary code with root privileges by uploading a specially formed archive containing the postinstall.sh file.
Recommendations
As a temporary workaround, consider disabling the webupgrade function until a patch is available.
Restrict access to the Cohu 3960HD to minimize the risk of exploitation.
Avoid using the webupgrade function to upload firmware until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cohu 3960Hd