Vulnerability Description
Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac, Hostname, or Alias field. NOTE: this may overlap CVE-2020-10818.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Articatech | Artica Proxy | < 4.30.000000 |
Related Weaknesses (CWE)
References
- https://github.com/InfoSec4Fun/CVE-2020-13159ExploitThird Party Advisory
- https://sourceforge.net/projects/artica-squid/files/ProductThird Party Advisory
- https://github.com/InfoSec4Fun/CVE-2020-13159ExploitThird Party Advisory
- https://sourceforge.net/projects/artica-squid/files/ProductThird Party Advisory
FAQ
What is CVE-2020-13159?
CVE-2020-13159 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac, Hostname, or Alias field. NOTE: this may overlap CVE-2020-10818.
How severe is CVE-2020-13159?
CVE-2020-13159 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-13159?
Check the references section above for vendor advisories and patch information. Affected products include: Articatech Artica Proxy.