ID:3054 - Exploit for Command Injection in InterScan Web Security Virtual Appliance (IWSVA) - CVE-2020-8605

 
Main Vulnerability Database Exploits ID:3054 - Exploit for Command Injection in InterScan Web Security Virtual Appliance (IWSVA) - CVE-2020-8605

ID:3054 - Exploit for Command Injection in InterScan Web Security Virtual Appliance (IWSVA) - CVE-2020-8605

Published: July 2, 2020


Vulnerability identifier: #VU28301
Vulnerability risk: Medium
CVE-ID: CVE-2020-8605
CWE-ID: CWE-77
Exploitation vector: Remote access
Vulnerable software:
InterScan Web Security Virtual Appliance (IWSVA)

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to execute arbitrary commands on the system.

The vulnerability exists due to improper input validation in the "mount_device" parameter within the "LogSettingHandler" class. A remote authenticated attacker can execute arbitrary commands on the target system.


Remediation

Install updates from vendor's website.