8.5
CVSSv2

CVE-2013-0526

Published: 21/08/2013 Updated: 29/08/2017
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
VMScore: 855
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) prior to 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) count or (2) size parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm global_console_manager_16_firmware

ibm global_console_manager_32_firmware

Exploits

I Product description The IBM 1754 GCM family provides KVM over IP and serial console management technology in a single appliance II Vulnerability information Impact: Command execution Remotely exploitable: yes CVE: 2013-0526 CVS Score: 85 III Vulnerability details GCM16 (v118022011) and older versions of this KVM switch contain a f ...