Vulnerability Description
LuaUPnP in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via the code parameter to /port_3480/data_request because the "No unsafe lua allowed" code block is skipped.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Getvera | Vera Edge Firmware | 1.7.4452 |
| Getvera | Vera Edge | - |
Related Weaknesses (CWE)
References
- https://distributedcompute.com/2019/07/13/vera-edge-home-controller-rce-via-unauExploitThird Party Advisory
- https://distributedcompute.com/2019/07/13/vera-edge-home-controller-rce-via-unauExploitThird Party Advisory
FAQ
What is CVE-2019-13598?
CVE-2019-13598 is a vulnerability with a CVSS score of 9.8 (CRITICAL). LuaUPnP in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via the code parameter to /port_3480/data_request because the "No unsafe lua allowed"...
How severe is CVE-2019-13598?
CVE-2019-13598 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-13598?
Check the references section above for vendor advisories and patch information. Affected products include: Getvera Vera Edge Firmware, Getvera Vera Edge.