Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems. * vulnerabilities: * Improper Neutralization of Special Elements used in a Command ('Command Injection') * Use of Hard-coded Credentials * Improper Authentication * Binding to an Unrestricted IP Address The vulnerability has been rated as critical.This issue affects ActADUR: from v2.0.1.9 before v2.0.2.0., hence updating to version v2.0.2.0. or above is required.
An attacker with local network access can exploit the lack of proper neutralization of special characters in commands (command injection) to execute arbitrary code on the server. Additionally, the product uses hard-coded credentials and has a flawed authentication mechanism, which allows access control to be bypassed. The server listens on an unrestricted IP address (Binding to an Unrestricted IP Address), which increases the attack surface — the service is available on all network interfaces of the host.
An attacker with local network access can take control of the host without authentication through remote code execution, and also obtain a high level of access to system resources and related systems (high values of VC, VI, SC, SI in CVSS).
ActADUR should be updated to version v2.0.2.0 or later. Detailed information is available in the manufacturer's guide at https://www.protns.com/53. Until the update is applied, it is recommended to restrict network access to the ActADUR server only to trusted network segments.
ActADUR in versions from v2.0.1.9 (inclusive) to v2.0.2.0 (exclusive), ProTNS product.
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X