Intellian Satellian Aptus Web远程下令执行误差危害通告
宣布时间 2020-02-10误差编号和级别
CVE编号:CVE-2020-7980,危险级别:严重,CVSS分值:9.8
影响版本
Intellian Satellian Aptus <= 1.24
误差概述
Intellian Satellian Aptus Web控制台保存远程代码执行误差。Intellian Aptus Web 1.24之前的版本,允许远程攻击者通过JSON数据中的Q字段向/cgi-bin/libagent.cgi 执行恣意OS下令。部分情形下需要有用的认证cookie才华登录并触发误差。
误差验证
PoC:https://github.com/Xh4H/Satellian-CVE-2020-7980。
修复建议
现在厂商已宣布新版本以修复误差,官网链接:https://www.intelliantech.com/?lang=en。
参考链接
https://nvd.nist.gov/vuln/detail/CVE-2020-7980


京公网安备11010802024551号