Overview
The Mutiny Technology virtual appliance contains a command injection vulnerability which could allow an attacker to inject commands into the appliance.
Description
CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') The Mutiny Technology virtual appliance contains a network interface menu which is vulnerable to command injection with root privileges. |
Impact
An authenticated attacker can run arbitrary commands on the appliance. |
Solution
Update |
Restrict access |
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | 2.1 | AV:N/AC:H/Au:S/C:N/I:P/A:N |
| Temporal | 1.4 | E:U/RL:OF/RC:UC |
| Environmental | 0.6 | CDP:L/TD:L/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Christopher Campbell for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
| CVE IDs: | CVE-2012-3001 |
| Date Public: | 2012-10-07 |
| Date First Published: | 2012-10-22 |
| Date Last Updated: | 2012-10-22 12:05 UTC |
| Document Revision: | 8 |