Description
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been rated as critical. This issue affects the function getenv of the file upload_file.cgi. The manipulation of the argument QUERY_STRING leads to command injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-273527. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the affected release tree is end-of-life.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48364 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been rated as critical. This issue affects the function getenv of the file upload_file.cgi. The manipulation of the argument QUERY_STRING leads to command injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-273527. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the affected release tree is end-of-life. |
References
History
Tue, 06 Aug 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vivotek
Vivotek sd9364 Vivotek sd9364 Firmware |
|
| CPEs | cpe:2.3:h:vivotek:sd9364:-:*:*:*:*:*:*:* cpe:2.3:o:vivotek:sd9364_firmware:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Vivotek
Vivotek sd9364 Vivotek sd9364 Firmware |
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-08-05T15:04:43.133Z
Reserved: 2024-08-02T21:36:40.547Z
Link: CVE-2024-7442
Updated: 2024-08-05T15:04:29.664Z
Status : Analyzed
Published: 2024-08-03T18:15:35.793
Modified: 2024-08-06T17:45:39.703
Link: CVE-2024-7442
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD