Lucene search

K
nvd[email protected]NVD:CVE-2018-20218
HistoryMar 21, 2019 - 4:00 p.m.

CVE-2018-20218

2019-03-2116:00:35
CWE-78
web.nvd.nist.gov
4

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.006

Percentile

78.0%

An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell command without any kind of escaping or validation in /usr/share/www/check.lp file. An attacker is able to perform command injection using the “password” parameter in the login form.

Affected configurations

Nvd
Node
teracueenc-400_hdmi_firmwareRange2.56
AND
teracueenc-400_hdmiMatch-
Node
teracueenc-400_hdmi2_firmwareRange2.56
AND
teracueenc-400_hdmi2Match-
Node
teracueenc-400_hdsdi_firmwareRange2.56
AND
teracueenc-400_hdsdiMatch-
VendorProductVersionCPE
teracueenc-400_hdmi_firmware*cpe:2.3:o:teracue:enc-400_hdmi_firmware:*:*:*:*:*:*:*:*
teracueenc-400_hdmi-cpe:2.3:h:teracue:enc-400_hdmi:-:*:*:*:*:*:*:*
teracueenc-400_hdmi2_firmware*cpe:2.3:o:teracue:enc-400_hdmi2_firmware:*:*:*:*:*:*:*:*
teracueenc-400_hdmi2-cpe:2.3:h:teracue:enc-400_hdmi2:-:*:*:*:*:*:*:*
teracueenc-400_hdsdi_firmware*cpe:2.3:o:teracue:enc-400_hdsdi_firmware:*:*:*:*:*:*:*:*
teracueenc-400_hdsdi-cpe:2.3:h:teracue:enc-400_hdsdi:-:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.006

Percentile

78.0%