PT-2020-19643 · Multitech · Multitech Conduit Mtcdt-Lvw2-24Xx
Published
2020-01-21
·
Updated
2020-01-29
·
CVE-2020-7594
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MultiTech Conduit MTCDT-LVW2-24XX version 1.4.17-ocea-13592
Description
The issue allows remote authenticated administrators to execute arbitrary OS commands. This can be achieved by navigating to the Debug Options page and entering shell metacharacters in the
interface JSON field of the ping function.Recommendations
For version 1.4.17-ocea-13592, as a temporary workaround, consider restricting access to the Debug Options page and the ping function until a patch is available. Avoid using the
interface JSON field in the ping function to minimize the risk of exploitation.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Multitech Conduit Mtcdt-Lvw2-24Xx