PT-2023-7478 · Unknown · Osprey Pump Controller

CVE-2023-27394

·

Publicado

2023-03-23

·

Atualizado

2023-04-05

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Osprey Pump Controller version 1.01
Description The issue exists due to the failure to neutralize special elements in the DataLogView.php, EventsView.php, and AlarmsView.php scripts of the Osprey Pump Controller software. This allows a remote attacker to execute arbitrary commands through an HTTP GET parameter. The vulnerability can be exploited to inject and execute arbitrary shell commands.
Recommendations For Osprey Pump Controller version 1.01, consider disabling the DataLogView.php, EventsView.php, and AlarmsView.php scripts until a patch is available to prevent exploitation of the unauthenticated OS command injection vulnerability. Restrict access to the HTTP GET parameter to minimize the risk of arbitrary command execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08522
CVE-2023-27394

Produtos afetados

Osprey Pump Controller