#VU14606 Command injection in Opsview Monitor - CVE-2018-16144
Published: September 5, 2018 / Updated: September 6, 2018
Opsview Monitor
Opsview
Description
The vulnerability exists in the test connection functionality due to an improper sanitization of the 'rancid_password' parameter. A remote attacker can automate the backing up of network devices' configuration files to a centralized location and execute arbitrary commands with elevated privileges.