PT-2020-20436 · Post Oak · Post Oak Awam Bluetooth Field Device
Published
2020-02-17
·
Updated
2020-02-20
·
CVE-2020-9021
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Post Oak AWAM Bluetooth Field Device versions 2011.3, 7400v2.02.01.2019, 7400v2.08.21.2018, 7800SD.2012.12.5, 7800SD.2015.1.16
Description
The issue allows for injections of operating system commands through timeconfig.py via shell metacharacters in the
htmlNtpServer parameter.Recommendations
For version 2011.3, consider disabling the timeconfig.py script until a patch is available.
For version 7400v2.02.01.2019, restrict access to the htmlNtpServer parameter to minimize the risk of exploitation.
For version 7400v2.08.21.2018, avoid using the
htmlNtpServer parameter in the affected API endpoint until the issue is resolved.
For version 7800SD.2012.12.5, consider temporarily removing the timeconfig.py functionality to prevent command injections.
For version 7800SD.2015.1.16, restrict the use of shell metacharacters in the htmlNtpServer parameter as a temporary workaround.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Post Oak Awam Bluetooth Field Device