PT-2020-9147 · Rpi · Rpi

Published

2020-02-24

·

Updated

2021-04-13

·

CVE-2019-10796

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions rpi versions 0.0.0 through 0.0.3
Description The issue allows execution of arbitrary commands. The variable pinNumbver in function GPIO within src/lib/gpio.js is used as part of the argument of exec function without any sanitization.
Recommendations For versions 0.0.0 through 0.0.3, consider disabling the GPIO function within src/lib/gpio.js to prevent exploitation until a proper fix is available. Restrict access to the exec function to minimize the risk of arbitrary command execution. Avoid using the variable pinNumbver in the affected function until the issue is resolved.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10796
GHSA-VF26-7GJF-F92R
SNYK-JS-RPI-548942

Affected Products

Rpi