10
CVSSv2

CVE-2015-9059

Published: 28/05/2017 Updated: 28/06/2020
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

picocom prior to 2.0 has a command injection vulnerability in the 'send and receive file' command because the command line is executed by /bin/sh unsafely.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

picocom project picocom

Vendor Advisories

Debian Bug report logs - #863671 CVE-2015-9059 Package: picocom; Maintainer for picocom is Matt Palmer <mpalmer@debianorg>; Source for picocom is src:picocom (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 29 May 2017 21:09:02 UTC Severity: grave Tags: security, upstream Found in ...