PT-2020-19216 · Schmid · Schmid Zi 620 V400 Vpn 090

Published

2020-02-06

·

Updated

2020-02-11

·

CVE-2020-6760

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Schmid ZI 620 V400 VPN 090 routers
Description The issue allows an attacker to execute OS commands as root via shell metacharacters to an entry on the SSH subcommand menu. This can be demonstrated by using the ping command.
Recommendations For Schmid ZI 620 V400 VPN 090 routers, consider restricting access to the SSH subcommand menu to minimize the risk of exploitation. As a temporary workaround, limit the use of shell metacharacters in the SSH subcommand menu until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6760

Affected Products

Schmid Zi 620 V400 Vpn 090