Vulnerability Description
Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by injecting malicious OGNL expressions. Attackers can send crafted requests to the login.action endpoint with OGNL payloads in the redirect parameter to instantiate ProcessBuilder objects and execute system commands with root privileges.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/47379
- https://www.vulncheck.com/advisories/epross-avcon6-ognl-remote-code-execution-vi
FAQ
What is CVE-2018-25159?
CVE-2018-25159 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by injecting m...
How severe is CVE-2018-25159?
CVE-2018-25159 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-25159?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.