PT-2019-3536 · Zingbox · Zingbox Inspector

Published

2019-10-01

·

Updated

2023-02-15

·

CVE-2019-1584

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zingbox Inspector versions 1.293 and earlier
Description A security issue exists that allows for remote code execution if the Inspector receives a malicious command from the Zingbox cloud or is tampered with to connect to an attacker's cloud endpoint. The vulnerability is also described as a result of insufficient input validation, which could allow a remote attacker to implement a "man-in-the-middle" attack.
Recommendations For Zingbox Inspector versions 1.293 and earlier, update to a version later than 1.293 to resolve the issue. As a temporary workaround, consider restricting access to the Zingbox cloud endpoint to minimize the risk of exploitation. Additionally, ensure that the Zingbox Inspector is not tampered with to connect to unauthorized cloud endpoints.

Fix

Command Injection

RCE

Weakness Enumeration

Related Identifiers

BDU:2019-03713
CVE-2019-1584

Affected Products

Zingbox Inspector