PT-2018-17099 · Open On Chip Debugger+1 · Openocd+1

Josef Gajdusek

·

Published

2018-01-16

·

Updated

2024-04-05

·

CVE-2018-5704

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Open On-Chip Debugger (OpenOCD) version 0.10.0
Description: The issue allows remote attackers to conduct cross-protocol scripting attacks and execute arbitrary commands via a crafted web site, by not blocking attempts to use HTTP POST for sending data to 127.0.0.1 port 4444.
Recommendations: For OpenOCD version 0.10.0, as a temporary workaround, consider restricting access to the HTTP POST endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Externally-Controlled Format String

Weakness Enumeration

Related Identifiers

ALT-PU-2021-4847
CVE-2018-5704
DLA-1253-1
DSA-4093-1

Affected Products

Alt Linux
Openocd