PT-2022-19689 · Unknown · Resi Gemini-Net
Alessandro Bosco
+3
·
Published
2022-05-12
·
Updated
2023-08-08
·
CVE-2022-29539
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
RESI Gemini-Net version 4.2
Description
The issue is related to OS Command Injection, where the software does not properly check the parameters sent as input before they are processed on the server. Due to the lack of validation of user input, an unauthenticated attacker can bypass the syntax intended by the software and inject arbitrary system commands with the privileges of the application user. This can be achieved by concatenating commands, such as
&|;r commands.Recommendations
For RESI Gemini-Net version 4.2, consider implementing input validation to prevent arbitrary system command injection. As a temporary workaround, restrict access to the resi-calltrace component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Resi Gemini-Net