PT-2020-17150 · V Sol · V-Sol V1600D+4

Alexandre Torres

+3

·

Published

2020-11-29

·

Updated

2021-07-21

·

CVE-2020-29381

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions V-SOL V1600D versions V2.03.57 through V2.03.69 V-SOL V1600D4L version V1.01.49 V-SOL V1600D-MINI version V1.01.48 V-SOL V1600G1 versions V1.9.7 through V2.0.7 V-SOL V1600G2 version V1.1.4
Description An issue was discovered in V-SOL OLT devices, where command injection can occur via a crafted filename in the CLI, specifically in the "upload tftp syslog" and "upload tftp configuration" commands.
Recommendations For V-SOL V1600D versions V2.03.57 through V2.03.69, consider disabling the "upload tftp syslog" and "upload tftp configuration" commands in the CLI until a patch is available. For V-SOL V1600D4L version V1.01.49, restrict access to the CLI to minimize the risk of exploitation. For V-SOL V1600D-MINI version V1.01.48, avoid using crafted filenames in the "upload tftp syslog" and "upload tftp configuration" commands. For V-SOL V1600G1 versions V1.9.7 through V2.0.7, consider implementing additional security measures to prevent command injection attacks. For V-SOL V1600G2 version V1.1.4, restrict access to the vulnerable commands in the CLI to prevent exploitation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29381

Affected Products

V-Sol V1600D
V-Sol V1600D-Mini
V-Sol V1600D4L
V-Sol V1600G1
V-Sol V1600G2