Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-66410
HistoryAug 12, 2023 - 12:00 a.m.

ScienceLogic SL1 Command Execution Vulnerability (CNVD-2023-66410)

2023-08-1200:00:00
China National Vulnerability Database
www.cnvd.org.cn
8
sciencelogic sl1
command execution
vulnerability
arp ping
data flow
workflow
system security
attacker

EPSS

0.001

Percentile

31.7%

ScienceLogic SL1 is an application from ScienceLogic, Inc. Connect your real estate together to automate multidirectional data flow and workflow. A command execution vulnerability exists in ScienceLogic SL1 11.1.2 and earlier versions, which stems from the ARP ping device tool feature failing to properly filter construct command special characters, commands, etc., which can be exploited by an attacker to execute arbitrary commands on the system.

EPSS

0.001

Percentile

31.7%

Related for CNVD-2023-66410