Overview
The Lantronix xPrintServer and its accompanying cloud storage API contains several vulnerabilities.
Description
CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') - CVE-2014-9002 An unauthenticated attacker can include a shell command inside the 'c' parameter of an AJAX request to the device, which is then executed in context of the device root. According to Lantronix, this issue was addressed in version 3.3.0. |
Impact
An unauthenticated remote attacker may be able to learn private information about the device's internal network, access or modify the device's configuration or files, or gain root access to the device. |
Solution
Apply an update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 8.3 | AV:A/AC:L/Au:N/C:C/I:C/A:C |
Temporal | 6.5 | E:POC/RL:OF/RC:C |
Environmental | 4.9 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to the reporter who wishes to remain anonymous.
This document was written by Garret Wassermann.
Other Information
CVE IDs: | CVE-2014-9002, CVE-2014-9003, CVE-2016-4325 |
Date Public: | 2016-05-13 |
Date First Published: | 2016-05-13 |
Date Last Updated: | 2016-05-13 22:43 UTC |
Document Revision: | 40 |