PT-2022-12473 · Pascom · Pascom Cloud Phone System

Published

2022-03-18

·

Updated

2022-07-12

·

CVE-2021-45966

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Pascom Cloud Phone System versions prior to 7.20.x
Description An issue was discovered in the management REST API, specifically at the "/services/apply" endpoint in exd.pl, allowing remote attackers to execute arbitrary code via shell metacharacters.
Recommendations For versions prior to 7.20.x, update to version 7.20.x or later to resolve the issue. As a temporary workaround, consider restricting access to the "/services/apply" endpoint in exd.pl to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-45966

Affected Products

Pascom Cloud Phone System