W Sangfor Operation and Maintenance Management System do wersji 3.0.8 zidentyfikowano podatność. Podatny element to funkcja SessionController w pliku /isomp-protocol/protocol/session, gdzie manipulacja parametrem Hostname prowadzi do os command injection. Atak może być wykonany zdalnie, a exploit jest publicznie dostępny. Vendor został powiadomiony wcześnie, ale nie odpowiedział.
▸ Pokaż oryginał (EN)
A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element is the function SessionController of the file /isomp-protocol/protocol/session. Such manipulation of the argument Hostname leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSangfor Operation And Maintenance Security Management System
APPSangfor≤ 3.0.8
Powiązane podatności
A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected b...
A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is...
W Sangfor Operation and Maintenance Security Management System do wersji 3.0.12 odkryto podatność. Zagrożona j...
W systemie Sangfor Operation and Maintenance Security Management System do wersji 3.0.12 odkryto lukę bezpiecz...
W Sangfor Operation and Maintenance Management System do wersji 3.0.8 odkryto lukę bezpieczeństwa. Podatny ele...