Lucene search

K
prionPRIOn knowledge basePRION:CVE-2018-14417
HistoryAug 04, 2018 - 1:29 a.m.

Command injection

2018-08-0401:29:00
PRIOn knowledge base
www.prio-n.com
5

9.9 High

AI Score

Confidence

High

0.686 Medium

EPSS

Percentile

98.0%

A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the ‘recentVersion’ parameter from the snserv endpoint, allowing an unauthenticated attacker to execute arbitrary commands with root permissions.

CPENameOperatorVersion
cloudlt4.0.3

9.9 High

AI Score

Confidence

High

0.686 Medium

EPSS

Percentile

98.0%