PT-2019-12259 · Intersect Alliance · Snare Central

Simone Quatrini

·

Published

2019-08-29

·

Updated

2019-09-03

·

CVE-2019-11364

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Snare Central versions prior to 7.4.5
Description The issue allows remote authenticated attackers to inject arbitrary OS commands. This is achieved via the FORMNAS share parameter in the ServerConf/DataManagement/DiskManager.php file.
Recommendations For versions prior to 7.4.5, update to version 7.4.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the ServerConf/DataManagement/DiskManager.php file to minimize the risk of exploitation. Avoid using the FORMNAS share parameter in the affected API endpoint until the issue is resolved.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11364

Affected Products

Snare Central