PT-2023-8528 · Vinchin · Vinchin Backup & Recovery
Gregory Boddin
·
Published
2023-10-25
·
Updated
2023-12-29
·
CVE-2023-45498
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Vinchin Backup & Recovery versions 5.0.* through 7.0.*
Description
The issue is related to a lack of input data sanitization, which can allow a remote attacker to execute arbitrary commands. This is a command injection vulnerability. The estimated number of potentially affected devices is not provided, and there is no information about real-world incidents where this issue was exploited.
Recommendations
For versions 5.0.* through 7.0.*, upgrade to version 7.2.0 to mitigate the issue.
As a temporary workaround, consider restricting access to API endpoints that may be vulnerable to command injection until a patch is available.
Avoid using hard-coded credentials in API ACLs to minimize the risk of exploitation.
Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vinchin Backup & Recovery