8.5
CVE-2013-0526
- EPSS 7.11%
- Veröffentlicht 21.08.2013 16:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) count or (2) size parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Global Console Manager 16 Firmware Version <= 1.18.0.22011
Ibm ≫ Global Console Manager 32 Firmware Version <= 1.18.0.22011
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 7.11% | 0.907 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.5 | 6.8 | 10 |
AV:N/AC:M/Au:S/C:C/I:C/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.