PT-2020-16373 · Systeminformation · Systeminformation

Sebhildebrandt

·

Published

2020-11-27

·

Updated

2020-12-03

·

CVE-2020-26245

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions systeminformation versions prior to 4.30.5
Description The issue is a command injection vulnerability caused by prototype pollution. It was fixed with a rewrite of shell sanitations to avoid prototype pollution problems.
Recommendations For versions prior to 4.30.5, upgrade to version 4.30.5 or later. If you cannot upgrade, be sure to check or sanitize service parameter strings that are passed to si.inetChecksite().

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-26245
GHSA-4V2W-H9JM-MQJG

Affected Products

Systeminformation