PT-2019-7933 · Mersive · Solstice Pod

Alexandre Teyar

·

Published

2019-11-27

·

Updated

2019-12-04

·

CVE-2017-12945

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Solstice Pod versions prior to 2.8.4
Description The issue is related to insufficient validation of user-supplied input for the networking configuration, which allows authenticated attackers to execute arbitrary commands as root.
Recommendations For versions prior to 2.8.4, update to version 2.8.4 or later to resolve the issue.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-12945

Affected Products

Solstice Pod