CVE-2018-14417

Scores

EPSS

0.711medium71.1%
0%20%40%60%80%100%

Percentile: 71.1%

CVSS

9.8critical3.x
0246810

CVSS Score: 9.8/10

All CVSS Scores

CVSS 3.x
9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
10.0

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Description

A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the ‘recentVersion’ parameter from the snserv endpoint, allowing an unauthenticated attacker to execute arbitrary commands with root permissions.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-78

Exploits

Exploit ID: 45097

Source: exploitdb

URL: https://www.exploit-db.com/exploits/45097

Vulnerable Software (1)

Type: Configuration

Vendor: *

Product: cloud

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:softnas:cloud:*:*:*:*:*:*:*:*",      "versionEndExcluding": "4.0.3",      "vulnerable": true    }  ],  "operator": "OR"}

Source: nvd

End of list