SB2018042515 - Multiple vulnerabilities in Vecna VGo Robot
Published: April 25, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) OS command injection (CVE-ID: CVE-2018-8866)
CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an adjacent attacker to execute arbitrary shell commands on the target system.
The weakness exists due to insufficient validation of user-supplied input. An adjacent attacker can inject and execute arbitrary shell commands.
Successful exploitation of the vulnerability may result in system compromise.
2) Information disclosure (CVE-ID: CVE-2018-8860)
CWE-ID: CWE-319 - Cleartext Transmission of Sensitive Information
CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows an adjacent attacker to obtain potentially sensitive information on the target system.
The weakness exists due to cleartext transmission of sensitive information. An adjacent attacker can capture firmware updates through the adjacent network.
Remediation
Install update from vendor's website.