Lucene search

K
nvd[email protected]NVD:CVE-2010-2892
HistoryNov 15, 2010 - 9:00 p.m.

CVE-2010-2892

2010-11-1521:00:03
CWE-20
web.nvd.nist.gov
7

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

7.2

Confidence

High

EPSS

0.024

Percentile

90.1%

gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the DRIVES parameter, as demonstrated by a cross-site request forgery (CSRF) attack.

Affected configurations

Nvd
Node
landeskmanagement_gatewayMatch4.0
OR
landeskmanagement_gatewayMatch4.0-1.48
OR
landeskmanagement_gatewayMatch4.2
OR
landeskmanagement_gatewayMatch4.2-1.8
VendorProductVersionCPE
landeskmanagement_gateway4.0cpe:2.3:h:landesk:management_gateway:4.0:*:*:*:*:*:*:*
landeskmanagement_gateway4.0-1.48cpe:2.3:h:landesk:management_gateway:4.0-1.48:*:*:*:*:*:*:*
landeskmanagement_gateway4.2cpe:2.3:h:landesk:management_gateway:4.2:*:*:*:*:*:*:*
landeskmanagement_gateway4.2-1.8cpe:2.3:h:landesk:management_gateway:4.2-1.8:*:*:*:*:*:*:*

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

7.2

Confidence

High

EPSS

0.024

Percentile

90.1%