SB2019052322 - OS Command Injection in Computrols CBAS Web



SB2019052322 - OS Command Injection in Computrols CBAS Web

Published: May 23, 2019 Updated: May 31, 2019

Security Bulletin ID SB2019052322
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) OS Command Injection (CVE-ID: CVE-2019-10854)

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to an incorrect neutralization of special elements when processing  intended OS command sent to a downstream component. A remote authenticated attacker can create a specially crafted command and execute arbitrary OS commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install update from vendor's website.