Input validation error in Fastjson - #VU23397
Published: December 4, 2019 / Updated: May 23, 2022
Vulnerability identifier: #VU23397
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted JSON data packets and execute arbitrary code on the target Fastjson server.
Affected software
Fastjson
FusionCompute
eSpace ECS
iManager NetEco 6000
iManager NetEco
RSE6500
FusionCompute
eSpace ECS
iManager NetEco 6000
iManager NetEco
RSE6500
Remediation
Install update from vendor's website.
FusionCompute - update to 8.0
RSE6500 - update to V500R002C00SPCh00
eSpace ECS - update to V300R001C00SPC221
iManager NetEco 6000 - update to V600R008C10SPC540
iManager NetEco - update to V600R008C30CP2402
RSE6500 - update to V500R002C00SPCh00
eSpace ECS - update to V300R001C00SPC221
iManager NetEco 6000 - update to V600R008C10SPC540
iManager NetEco - update to V600R008C30CP2402