We found results for “”
WS-2019-0224
Good to know:
Date: September 9, 2019
local-devices all versions are vulnerable to command injection when not validating input on ip addresses and concatenates it to an exec call, allowing attackers to run arbitrary commands in the system.
Language: JS
Severity Score
Severity Score
Top Fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | NONE |