Description
A vulnerability has been found in UTT HiPER 810 1.7.4-141218. This issue affects the function setSysAdm of the file /goform/formUser. The manipulation of the argument passwd1 leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:PCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:RCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:RAV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:URAffected Products
| Vendor | Product | Affected versions |
|---|---|---|
| UTT | HiPER 810 | 1.7.4-141218 |
References
5 LinksRecord Details
More from UTT
UTT 进取 521G setSysAdm doSystem command injection
UTT HiPER 520 Web Management formReleaseConnect sub_44EFB4 os command injection
UTT HiPER 520 Web Management formPdbUpConfig sub_44D264 os command injection
UTT 进取 521G formPdbUpConfig sub_446B18 os command injection
Related Tool Categories
Tool categories that test for or protect against this vulnerability class.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.