PT-2020-20436 · Post Oak · Post Oak Awam Bluetooth Field Device

Published

2020-02-17

·

Updated

2020-02-20

·

CVE-2020-9021

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Post Oak AWAM Bluetooth Field Device versions 2011.3, 7400v2.02.01.2019, 7400v2.08.21.2018, 7800SD.2012.12.5, 7800SD.2015.1.16
Description The issue allows for injections of operating system commands through timeconfig.py via shell metacharacters in the htmlNtpServer parameter.
Recommendations For version 2011.3, consider disabling the timeconfig.py script until a patch is available. For version 7400v2.02.01.2019, restrict access to the htmlNtpServer parameter to minimize the risk of exploitation. For version 7400v2.08.21.2018, avoid using the htmlNtpServer parameter in the affected API endpoint until the issue is resolved. For version 7800SD.2012.12.5, consider temporarily removing the timeconfig.py functionality to prevent command injections. For version 7800SD.2015.1.16, restrict the use of shell metacharacters in the htmlNtpServer parameter as a temporary workaround.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9021

Affected Products

Post Oak Awam Bluetooth Field Device