PT-2021-12473 · Nec · Univerge Sv8500+1
Published
2021-01-13
·
Updated
2021-01-21
·
CVE-2020-5685
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
UNIVERGE SV9500 series from V1 to V7
UNIVERGE SV8500 series from S6 to S8
Description:
The issue allows an attacker to execute arbitrary OS commands or cause a denial-of-service (DoS) condition by sending a specially crafted request to a specific URL.
Recommendations:
For UNIVERGE SV9500 series from V1 to V7, restrict access to the specific URL to minimize the risk of exploitation.
For UNIVERGE SV8500 series from S6 to S8, consider implementing additional security measures to prevent specially crafted requests from being processed.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Univerge Sv8500
Univerge Sv9500