PT-2022-11642 · Printerlogic · Printerlogic Web Stack
Published
2022-02-01
·
Updated
2022-02-02
·
CVE-2021-42638
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below
Description
The issue is related to the lack of sanitization of user input, resulting in pre-auth remote code execution.
Recommendations
For PrinterLogic Web Stack versions 19.1.1.13 SP9 and below, consider updating to a version above 19.1.1.13 SP9 to resolve the issue. As a temporary workaround, restrict access to the web stack to minimize the risk of exploitation.
Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Printerlogic Web Stack