Vulnerability Description
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not sanitized in networkdiags.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Columbiaweather | Weather Microserver Firmware | ms_2.6.9900 |
| Columbiaweather | Weather Microserver | - |
Related Weaknesses (CWE)
References
- https://applied-risk.com/labs/advisoriesThird Party Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-19-078-02Third Party AdvisoryUS Government Resource
- https://applied-risk.com/labs/advisoriesThird Party Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-19-078-02Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2018-18879?
CVE-2018-18879 is a vulnerability with a CVSS score of 8.8 (HIGH). In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not sanitized in networkdiags....
How severe is CVE-2018-18879?
CVE-2018-18879 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-18879?
Check the references section above for vendor advisories and patch information. Affected products include: Columbiaweather Weather Microserver Firmware, Columbiaweather Weather Microserver.