PT-2019-10733 · Cujo · Cujo Smart Firewall

Published

2019-03-21

·

Updated

2023-02-02

·

CVE-2018-3969

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CUJO Smart Firewall (affected versions not specified)
Description A vulnerability exists in the verified boot protection, allowing a local attacker to add arbitrary shell commands into the dhcpd.conf file. These commands persist across reboots and firmware updates, enabling the execution of unverified commands. The attacker must be able to write into /config/dhcpd.conf to trigger this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2018-3969

Affected Products

Cujo Smart Firewall