Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by injecting malicious OGNL expressions. Attackers can send crafted requests to the login.action endpoint with OGNL payloads in the redirect parameter to instantiate ProcessBuilder objects and execute system commands with root privileges.
The attacker sends a crafted HTTP request to the login.action endpoint, placing a malicious OGNL expression in the redirect parameter. The platform processes the passed parameter without proper validation, allowing injection and execution of arbitrary code on the server side. Through the OGNL expression, the attacker can create instances of ProcessBuilder objects and use them to execute arbitrary system commands with root privileges.
An unauthenticated attacker can gain full control over the system by executing arbitrary commands with root privileges, which may lead to complete server takeover, data theft, and further lateral movement within the network.
Patches available from the vendor should be applied according to the references. Additionally, until the fix is deployed, it is recommended to restrict network access to the login.action endpoint using firewall or ACL rules and monitor requests containing suspicious values of the redirect parameter.
Epross AVCON6 management platform — specific versions indicated in the vendor references and VulnCheck advisories
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X