PT-2022-20163 · Wwbn · Avideo

Claudio Bozzato

·

Published

2022-08-22

·

Updated

2022-08-26

·

CVE-2022-30534

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WWBN AVideo versions 11.6
Description An OS command injection issue exists in the aVideoEncoder chunkfile functionality. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this issue.
Recommendations For version 11.6, consider restricting access to the aVideoEncoder chunkfile functionality until a patch is available. As a temporary workaround, avoid using the vulnerable functionality in the dev master commit 3f7c0364 until a fix is provided.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-30534

Affected Products

Avideo