Vulnerability Description
In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts and lib/ping.ts). The vulnerability arises from insufficient input validation combined with a missing authorization check.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Genieacs | Genieacs | >= 1.2.0, < 1.2.8 |
Related Weaknesses (CWE)
References
- https://github.com/genieacs/genieacs/commit/7f295beeecc1c1f14308a93c82413bb33404PatchThird Party Advisory
- https://github.com/genieacs/genieacs/releases/tag/v1.2.8Release NotesThird Party Advisory
- https://github.com/genieacs/genieacs/commit/7f295beeecc1c1f14308a93c82413bb33404PatchThird Party Advisory
- https://github.com/genieacs/genieacs/releases/tag/v1.2.8Release NotesThird Party Advisory
FAQ
What is CVE-2021-46704?
CVE-2021-46704 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts and lib/ping.ts). The vulnerability arises from ins...
How severe is CVE-2021-46704?
CVE-2021-46704 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-46704?
Check the references section above for vendor advisories and patch information. Affected products include: Genieacs Genieacs.