7.7

CVE-2018-0512

Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to execute arbitrary OS commands via unspecified vectors.

Data is provided by the National Vulnerability Database (NVD)
IodataHdl-xr Firmware Version <= 2.01
   IodataHdl-xr Version-
IodataHdl-xrw Firmware Version <= 2.01
   IodataHdl-xrw Version-
IodataHdl-xr2u Firmware Version <= 2.01
   IodataHdl-xr2u Version-
IodataHdl-xr2uw Firmware Version <= 2.01
   IodataHdl-xr2uw Version-
IodataHdl-xv Firmware Version <= 1.50
   IodataHdl-xv Version-
IodataHdl-xvw Firmware Version <= 1.50
   IodataHdl-xvw Version-
IodataHdl-gt Firmware Version <= 1.37
   IodataHdl-gt Version-
IodataHdl-gtr Firmware Version <= 1.37
   IodataHdl-gtr Version-
IodataHdl-a Firmware Version <= 1.26
   IodataHdl-a Version-
IodataHdl-ah Firmware Version <= 1.26
   IodataHdl-ah Version-
IodataHdl2-a Firmware Version <= 1.26
   IodataHdl2-a Version-
IodataHdl2-ah Firmware Version <= 1.26
   IodataHdl2-ah Version-
IodataHdl-t Firmware Version <= 1.12
   IodataHdl-t Version-
IodataHls-c Firmware Version <= 1.12
   IodataHls-c Version-
IodataHvl-a Firmware Version <= 2.04
   IodataHvl-a Version-
IodataHvl-at Firmware Version <= 2.04
   IodataHvl-at Version-
IodataHvl-ata Firmware Version <= 2.04
   IodataHvl-ata Version-
IodataHvl-s Firmware Version <= 1.00
   IodataHvl-s Version-
IodataHfas1 Firmware Version <= 1.40
   IodataHfas1 Version-
IodataWhg-napg Firmware Version <= 1.08
   IodataWhg-napg Version-
IodataWhg-napga Firmware Version <= 1.08
   IodataWhg-napga Version-
IodataWhg-napgal Firmware Version <= 1.05
   IodataWhg-napgal Version-
IodataWhg-ac1750a Firmware Version <= 3.00
   IodataWhg-ac1750a Version-
IodataWhg-ac1750 Firmware Version <= 1.07
   IodataWhg-ac1750 Version-
IodataWhg-ac1750al Firmware Version <= 1.07
   IodataWhg-ac1750al Version-
IodataWn-ax1167gr Firmware Version <= 3.11
   IodataWn-ax1167gr Version-
IodataWn-gx300gr Firmware Version <= 2.00
   IodataWn-gx300gr Version-
IodataWnpr2600g Firmware Version <= 1.01
   IodataWnpr2600g Version-
IodataWnpr1750g Firmware Version <= 1.01
   IodataWnpr1750g Version-
IodataWnpr1167g Firmware Version <= 1.00
   IodataWnpr1167g Version-
IodataWnpr1167f Firmware Version <= 1.00
   IodataWnpr1167f Version-
IodataWn-ag750dgr Firmware Version <= 1.08
   IodataWn-ag750dgr Version-
IodataWn-g300r Firmware Version <= 1.14
   IodataWn-g300r Version-
IodataWn-g300r3 Firmware Version <= 1.04
   IodataWn-g300r3 Version-
IodataWn-ag300dgr Firmware Version <= 1.05
   IodataWn-ag300dgr Version-
IodataWn-ac1600dgr Firmware Version <= 2.06
   IodataWn-ac1600dgr Version-
IodataWn-ac1167dgr Firmware Version <= 1.02
   IodataWn-ac1167dgr Version-
IodataWn-g300ex Firmware Version <= 1.01
   IodataWn-g300ex Version-
IodataWn-ac1300ex Firmware Version <= 1.02
   IodataWn-ac1300ex Version-
IodataWn-ac583trk Firmware Version <= 1.05
   IodataWn-ac583trk Version-
IodataWn-ac583rk Firmware Version <= 1.06
   IodataWn-ac583rk Version-
IodataWn-g300sr Firmware Version <= 1.00
   IodataWn-g300sr Version-
IodataBx-vp1 Firmware Version <= 2.01
   IodataBx-vp1 Version-
IodataGv-ntx1 Firmware Version <= 1.02.00
   IodataGv-ntx1 Version-
IodataGv-ntx2 Firmware Version <= 1.02.00
   IodataGv-ntx2 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.25% 0.485
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 0.9 5.9
CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.7 5.1 10
AV:A/AC:L/Au:S/C:C/I:C/A:C
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.