A shell command injection in the HW Events SNMP community in XoruX LPAR2RRD and STOR2RRD before 7.30 allows authenticated remote attackers to execute arbitrary shell commands as the user running the service.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HXorux Lpar2rrd
APPXorux< 7.30Xorux Stor2rrd
APPXorux< 7.30
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Command Injection
CWE
Powiązane podatności
CVE-2021-42371CRITICAL9.8PL ✓ten sam produkt
Hardkodowane konto systemowe w XoruX LPAR2RRD i STOR2RRD
CVE-2020-24032CRITICAL9.8PL ✓ten sam produkt
Command injection w XoruX LPAR2RRD i STOR2RRD przez parametr strefy czasowej
CVE-2014-4981CRITICAL9.8PL ✓ten sam produkt
Command Injection w LPAR2RRD — zdalne wykonanie poleceń systemowych
CVE-2014-4982CRITICAL9.8PL ✓ten sam produkt
Command injection w Xorux LPAR2RRD — zdalne wykonanie poleceń
CVE-2025-54769HIGH8.8ten sam produkt
An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file...