Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Device42 Remote Collector before 17.05.01 does not sanitize user input in its SNMP Connectivity utility. This allows an authenticated attacker (with access to the console application) to execute arbitrary OS commands and escalate privileges.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Device42 Remote Collector 操作系统命令注入漏洞
Vulnerability Description
Device42 Remote Collector是美国Device42公司的一个虚拟设备,有助于跨网络的 SNMP、IPMI、虚拟机管理程序和其他自动发现,只需要 https 访问,无需跨网段打开大量端口。 Device42 Remote Collector 存在安全漏洞,该漏洞源于17.05.01 之前的 Device42 远程收集器不会清理其 SNMP 连接实用程序中的用户输入。 攻击者可利用该漏洞(可以访问控制台应用程序)执行任意操作系统命令并提升权限。
CVSS Information
N/A
Vulnerability Type
N/A