Lucene search

K
cveMitreCVE-2010-2892
HistoryNov 15, 2010 - 9:00 p.m.

CVE-2010-2892

2010-11-1521:00:03
CWE-20
mitre
web.nvd.nist.gov
27
cve-2010-2892
landesk management gateway
remote code execution
authentication bypass
command injection
csrf attack

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

7.3

Confidence

High

EPSS

0.024

Percentile

90.1%

gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the DRIVES parameter, as demonstrated by a cross-site request forgery (CSRF) attack.

Affected configurations

Nvd
Node
landeskmanagement_gatewayMatch4.0
OR
landeskmanagement_gatewayMatch4.0-1.48
OR
landeskmanagement_gatewayMatch4.2
OR
landeskmanagement_gatewayMatch4.2-1.8
VendorProductVersionCPE
landeskmanagement_gateway4.0cpe:2.3:h:landesk:management_gateway:4.0:*:*:*:*:*:*:*
landeskmanagement_gateway4.0-1.48cpe:2.3:h:landesk:management_gateway:4.0-1.48:*:*:*:*:*:*:*
landeskmanagement_gateway4.2cpe:2.3:h:landesk:management_gateway:4.2:*:*:*:*:*:*:*
landeskmanagement_gateway4.2-1.8cpe:2.3:h:landesk:management_gateway:4.2-1.8:*:*:*:*:*:*:*

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

7.3

Confidence

High

EPSS

0.024

Percentile

90.1%