PT-2019-10733 · Cujo · Cujo Smart Firewall

CVE-2018-3969

·

Publicado

2019-03-21

·

Atualizado

2023-02-02

CVSS v3.1

8.2

Alta

VetorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CUJO Smart Firewall (affected versions not specified)
Description A vulnerability exists in the verified boot protection, allowing a local attacker to add arbitrary shell commands into the dhcpd.conf file. These commands persist across reboots and firmware updates, enabling the execution of unverified commands. The attacker must be able to write into /config/dhcpd.conf to trigger this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-3969

Produtos afetados

Cujo Smart Firewall