PT-2018-13422 · Opsview · Opsview Monitor

Published

2018-09-05

·

Updated

2019-10-03

·

CVE-2018-16144

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Opsview Monitor versions prior to 5.3.1 Opsview Monitor versions 5.4.x prior to 5.4.2
Description The issue arises from improper sanitization of the rancid password parameter in the test connection functionality of the NetAudit section, leading to command injection.
Recommendations For versions prior to 5.3.1, update to version 5.3.1 or later. For versions 5.4.x prior to 5.4.2, update to version 5.4.2 or later.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16144

Affected Products

Opsview Monitor