PT-2020-11955 · Comtrend · Comtrend Vr-3033

Raki Ben Hamouda

·

Published

2020-03-05

·

Updated

2020-07-11

·

CVE-2020-10173

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Comtrend VR-3033 DE11-416SSG-C01 R02.A2pvI042j1.d26m
Description The issue concerns Multiple Authenticated Command Injection vulnerabilities. These vulnerabilities can be exploited via the ping and traceroute diagnostic pages. Specifically, the pingIpAddress parameter to ping.cgi is vulnerable to shell metacharacters.
Recommendations For Comtrend VR-3033 DE11-416SSG-C01 R02.A2pvI042j1.d26m, as a temporary workaround, consider restricting access to the ping and traceroute diagnostic pages until a patch is available. Avoid using the pingIpAddress parameter in the affected ping.cgi endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10173

Affected Products

Comtrend Vr-3033