PT-2023-7429 · Unknown · Osprey Pump Controller
Published
2023-03-23
·
Updated
2023-04-05
·
CVE-2023-27886
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Osprey Pump Controller version 1.01
Description
The issue is related to an unauthenticated OS command injection vulnerability. This vulnerability can be exploited to inject and execute arbitrary shell commands through a HTTP POST parameter. The parameter is called by the index.php script.
Recommendations
For Osprey Pump Controller version 1.01, consider disabling the HTTP POST parameter in the index.php script as a temporary workaround until a patch is available. Restrict access to the index.php script to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Osprey Pump Controller