PT-2018-17304 · Silex+1 · Silex Sd-320An+1

Published

2018-05-09

·

Updated

2018-06-13

·

CVE-2018-6021

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Silex SD-320AN versions 2.01 and prior GE MobileLink(GEH-SD-320AN) versions GEH-1.1 and prior
Description The issue is related to a system call parameter that is not properly sanitized, which may allow remote code execution.
Recommendations For Silex SD-320AN versions 2.01 and prior, consider restricting access to the system call until a patch is available. For GE MobileLink(GEH-SD-320AN) versions GEH-1.1 and prior, avoid using the vulnerable system call parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-6021

Affected Products

Ge Mobilelink
Silex Sd-320An