Vulnerability Description
In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsafe user supplied data (forms, cookies, HTTP headers etc.) to a system shell. In this attack, the attacker-supplied operating system commands are usually executed with the privileges of the vulnerable application. Command injection attacks are possible largely due to insufficient input validation.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Versa-Networks | Versa Director | - |
Related Weaknesses (CWE)
References
- https://hackerone.com/reports/1168198Third Party Advisory
- https://hackerone.com/reports/1168198Third Party Advisory
FAQ
What is CVE-2019-25029?
CVE-2019-25029 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are poss...
How severe is CVE-2019-25029?
CVE-2019-25029 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-25029?
Check the references section above for vendor advisories and patch information. Affected products include: Versa-Networks Versa Director.