9

CVE-2020-21883

Exploit
Unibox U-50 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a OS command injection vulnerability in /tools/ping, which can leads to complete device takeover.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Indionetworks ≫ Unibox U50 Firmware Version 2.4
   Indionetworks ≫ Unibox U50 Version -
Indionetworks ≫ Unibox U500 Firmware Version 2.4
   Indionetworks ≫ Unibox U500 Version -
Indionetworks ≫ Unibox U1000 Firmware Version 2.4
   Indionetworks ≫ Unibox U1000 Version -
Indionetworks ≫ Unibox U2500 Firmware Version 2.4
   Indionetworks ≫ Unibox U2500 Version -
Indionetworks ≫ Unibox U5000 Firmware Version 2.4
   Indionetworks ≫ Unibox U5000 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.06% 0.896
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://www.mail-archive.com/fulldisclosure%40seclists.org/msg07140.html
https://www.mail-archive.com/fulldisclosure@seclists.org/msg07140.html
https://s3curityb3ast.github.io/KSA-Dev-009.txt
Third Party Advisory
Exploit