Overview
The Mutiny Technology virtual appliance contains a command injection vulnerability which could allow an attacker to inject commands into the appliance.
Description
CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') The Mutiny Technology virtual appliance contains a network interface menu which is vulnerable to command injection with root privileges. |
Impact
An authenticated attacker can run arbitrary commands on the appliance. |
Solution
Update |
Restrict access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 2.1 | AV:N/AC:H/Au:S/C:N/I:P/A:N |
Temporal | 1.4 | E:U/RL:OF/RC:UC |
Environmental | 0.6 | CDP:L/TD:L/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Christopher Campbell for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2012-3001 |
Date Public: | 2012-10-07 |
Date First Published: | 2012-10-22 |
Date Last Updated: | 2012-10-22 12:05 UTC |
Document Revision: | 8 |