Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in BG-TEK Informatics Security Technologies CoslatV3 allows Command Injection, Privilege Escalation. This issue affects CoslatV3: through 3.1069. NOTE: The vendor was contacted and it was learned that the product is not supported.
The vulnerability results from improper neutralization of special characters in system commands (OS Command Injection) and improper control of code generation (Code Injection). A local, authenticated user can inject malicious commands or code that will be executed in the operating system context. The vulnerability allows for privilege escalation, which can lead to system takeover.
An attacker can execute arbitrary system commands and obtain higher privileges, which threatens the confidentiality, integrity, and availability of both the local system and related systems.
The manufacturer confirmed lack of support for the product — an official patch will not be released. It is recommended to immediately discontinue the product or isolate the system from the network and restrict local access to trusted users only until migration to a supported solution.
BG-TEK Informatics Security Technologies CoslatV3 in all versions up to and including 3.1069.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XBg Tek Coslat
APPBg-Tek3.0 – 3.1069