Zurück zur CVE-Übersicht
CVE-2014-9002
CRITICAL(10.0)AV:N/AC:L/Au:N/C:C/I:C/A:C
Risk Signal Score27/100 — MITTEL
- CVSS 10 — Kritisch
EPSS-Score
5%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
10
Technische Schwere
Beschreibung
Lantronix xPrintServer does not properly restrict access to ips/, which allows remote attackers to execute arbitrary commands via the c parameter in an rpc action.
Referenzen
- http://i.imgur.com/gjbZhXZ.png
- http://packetstormsecurity.com/files/129091/Lantronix-xPrintServer-Remote-Comman...
- http://seclists.org/fulldisclosure/2014/Nov/24
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98644
- http://i.imgur.com/gjbZhXZ.png
- http://packetstormsecurity.com/files/129091/Lantronix-xPrintServer-Remote-Comman...
- http://seclists.org/fulldisclosure/2014/Nov/24
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98644