PT-2021-22843 · Rittal · Rittal Cmc Pu Iii
Asang17
·
Published
2021-09-09
·
Updated
2021-09-22
·
CVE-2021-40222
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Rittal CMC PU III Web management versions V3.11.00 2 through V3.17.10
Description
The issue is related to a remote code execution vulnerability. It is possible to introduce shell code to create a reverse shell in the
PU-Hostname field of the TCP/IP Configuration dialog. The web application fails to sanitize user input on the Network TCP/IP configuration page, allowing an attacker to inject commands as root on the device, which will be executed once the data is received.Recommendations
For versions V3.11.00 2 through V3.17.10, update to a version later than V3.17.10 to resolve the issue.
As a temporary workaround, consider restricting access to the TCP/IP Configuration dialog to minimize the risk of exploitation.
Avoid using the
PU-Hostname field in the TCP/IP Configuration dialog until the issue is resolved.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rittal Cmc Pu Iii