CVE-2017-6334
HIGH(8.8)KEVWahrscheinlich ausgenutzt
NETGEAR DGN2200 Devices OS Command Injection Vulnerability
Beschreibung
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different vulnerability than CVE-2017-6077.
KEV-Informationen
CVSS-Score
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HIm Rechner öffnenBetroffene Produkte
| Hersteller | Produkt | Version |
|---|---|---|
| netgear | dgn2200 series firmware | <= 10.0.0.50 |
Mehrere CVSS-Bewertungen
Quelle: [email protected](Primary)
8.8
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Quelle: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
8.8
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Referenzen
- http://www.securityfocus.com/bid/96463(Broken Link, Third Party Advisory, VDB Entry)
- https://www.exploit-db.com/exploits/41459/(Exploit, Third Party Advisory, VDB Entry)
- https://www.exploit-db.com/exploits/41472/(Exploit, Third Party Advisory, VDB Entry)
- https://www.exploit-db.com/exploits/42257/(Exploit, Third Party Advisory, VDB Entry)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6334(US Government Resource)
Hilfe beim Schwachstellenmanagement?
Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.