PT-2023-7429 · Unknown · Osprey Pump Controller

Published

2023-03-23

·

Updated

2023-04-05

·

CVE-2023-27886

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Osprey Pump Controller version 1.01
Description The issue is related to an unauthenticated OS command injection vulnerability. This vulnerability can be exploited to inject and execute arbitrary shell commands through a HTTP POST parameter. The parameter is called by the index.php script.
Recommendations For Osprey Pump Controller version 1.01, consider disabling the HTTP POST parameter in the index.php script as a temporary workaround until a patch is available. Restrict access to the index.php script to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2023-08468
CVE-2023-27886

Affected Products

Osprey Pump Controller