PT-2020-19571 · Cayin · Cayin Cms-60+4
Gjoko Krstic
·
Published
2020-08-06
·
Updated
2024-08-20
·
CVE-2020-7357
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cayin CMS versions 7.5 through 8.2
Cayin CME-SE version (affected versions not specified)
Cayin CMS-60 version (affected versions not specified)
Cayin CMS-40 version (affected versions not specified)
Cayin CMS-20 version (affected versions not specified)
Description
The issue is an authenticated OS semi-blind command injection vulnerability that can be exploited using default credentials. It allows the injection and execution of arbitrary shell commands as the root user through the
NTP Server IP HTTP POST parameter in the system.cgi page.Recommendations
For Cayin CMS versions 7.5 through 8.2, consider disabling the
NTP Server IP parameter in the system.cgi page as a temporary workaround until a patch is available.
For Cayin CME-SE, CMS-60, CMS-40, and CMS-20, restrict access to the system.cgi page to minimize the risk of exploitation, as the affected versions are not specified.
Avoid using the NTP Server IP parameter in the system.cgi page until the issue is resolved.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cayin Cme-Se
Cayin Cms
Cayin Cms-20
Cayin Cms-40
Cayin Cms-60