PT-2023-7429 · Unknown · Osprey Pump Controller

CVE-2023-27886

·

Publicado

2023-03-23

·

Atualizado

2023-04-05

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Osprey Pump Controller version 1.01
Description The issue is related to an unauthenticated OS command injection vulnerability. This vulnerability can be exploited to inject and execute arbitrary shell commands through a HTTP POST parameter. The parameter is called by the index.php script.
Recommendations For Osprey Pump Controller version 1.01, consider disabling the HTTP POST parameter in the index.php script as a temporary workaround until a patch is available. Restrict access to the index.php script to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08468
CVE-2023-27886

Produtos afetados

Osprey Pump Controller