#VU23185 Command Injection in DMC-STRO - CVE-2019-18184

 

#VU23185 Command Injection in DMC-STRO - CVE-2019-18184

Published: December 2, 2019


Vulnerability identifier: #VU23185
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber
CVE-ID: CVE-2019-18184
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
DMC-STRO
Software vendor:
Crestron Electronics

Description

The vulnerability allows a remote attacker to execute arbitrary commands on the target system.

The vulnerability exists due to a lack of input validation in the Bash Command Substitution on the "ping" command parameters. A remote attacker can execute arbitrary commands on the device on behalf of the root user.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links