Description
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Vivotek IB8367A VVTK-0100b. Affected is the function getenv of the file upload_file.cgi. The manipulation of the argument QUERY_STRING leads to command injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-273528. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the affected release tree is end-of-life.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48365 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Vivotek IB8367A VVTK-0100b. Affected is the function getenv of the file upload_file.cgi. The manipulation of the argument QUERY_STRING leads to command injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-273528. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the affected release tree is end-of-life. |
References
History
Tue, 06 Aug 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vivotek ib8367a Firmware
|
|
| CPEs | cpe:2.3:o:vivotek:ib8367a_firmware:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Vivotek ib8367a Firmware
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-08-05T18:43:32.506Z
Reserved: 2024-08-02T21:36:43.428Z
Link: CVE-2024-7443
Updated: 2024-08-05T18:43:25.551Z
Status : Analyzed
Published: 2024-08-03T19:15:42.590
Modified: 2024-08-06T17:47:12.660
Link: CVE-2024-7443
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD