Insufficient verification of data authenticity in Zingbox Inspector - CVE-2019-1584
Published: October 3, 2019
Zingbox Inspector
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise the affected system.
the vulnerability exists due to Zingbox Inspector accepts and executes commands sent from a trusted Zingbox cloud, authenticated with PKI. A remote attacker with ability to perform man-in-the-middle (MitM) attack can execute arbitrary commands on the affected system.