PT-2020-14805 · Geeni · G-Cam+1
Published
2020-08-14
·
Updated
2020-08-19
·
CVE-2020-16205
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
G-Cam and G-Code versions 1.12.0.25 and prior
G-Cam and G-Code versions 1.12.13.2
G-Cam and G-Code versions 1.12.14.5
Description
A remote authenticated user can execute commands as root using a specially crafted URL command.
Recommendations
For G-Cam and G-Code versions 1.12.0.25 and prior, update to a version later than 1.12.0.25 to resolve the issue.
For G-Cam and G-Code version 1.12.13.2, consider disabling remote command execution until a patch is available.
For G-Cam and G-Code version 1.12.14.5, restrict access to the URL command functionality to minimize the risk of exploitation.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
G-Cam
G-Code