Main
Vulnerability Database
Exploits
ID:3054 - Exploit for Command Injection in InterScan Web Security Virtual Appliance (IWSVA) - CVE-2020-8605
ID:3054 - Exploit for Command Injection in InterScan Web Security Virtual Appliance (IWSVA) - CVE-2020-8605
Published: July 2, 2020
Vulnerability identifier: #VU28301
Vulnerability risk: Medium
CVE-ID: CVE-2020-8605
CWE-ID: CWE-77
Exploitation vector: Remote access
Vulnerable software:
InterScan Web Security Virtual Appliance (IWSVA)
InterScan Web Security Virtual Appliance (IWSVA)
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to execute arbitrary commands on the system.
The vulnerability exists due to improper input validation in the "mount_device" parameter within the "LogSettingHandler" class. A remote authenticated attacker can execute arbitrary commands on the target system.
Remediation
Install updates from vendor's website.