Vulnerability Description
cgi-bin/cmh/webcam.sh in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via --output argument injection in the username parameter to /cgi-bin/cmh/webcam.sh.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Getvera | Vera Edge Firmware | 1.7.4452 |
| Getvera | Vera Edge | - |
Related Weaknesses (CWE)
References
- https://distributedcompute.com/2019/08/22/vera-edge-home-controller-remote-shellExploitThird Party Advisory
- https://distributedcompute.com/2019/08/22/vera-edge-home-controller-remote-shellExploitThird Party Advisory
FAQ
What is CVE-2019-15498?
CVE-2019-15498 is a vulnerability with a CVSS score of 8.8 (HIGH). cgi-bin/cmh/webcam.sh in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via --output argument injection in the username parameter to /cgi-bin/c...
How severe is CVE-2019-15498?
CVE-2019-15498 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-15498?
Check the references section above for vendor advisories and patch information. Affected products include: Getvera Vera Edge Firmware, Getvera Vera Edge.