PT-2018-13047 · Ucopia · Ucopia Wireless Appliance
Published
2018-08-21
·
Updated
2019-10-03
·
CVE-2018-15481
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UCOPIA Wireless Appliance firmware versions 5.1.x before 5.1.13
Description
The issue is related to improper input sanitization within the restricted administration shell. This allows authenticated remote attackers to escalate their privileges by modifying the SSH configuration file. Specifically, attackers can add a LocalCommand to the file in the user home folder, enabling them to escape the shell.
Recommendations
For firmware versions 5.1.x before 5.1.13, update to version 5.1.13 or later to resolve the issue. As a temporary workaround, consider restricting access to the SSH configuration file in the user home folder to prevent unauthorized modifications.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ucopia Wireless Appliance