9
CVSSv2

CVE-2017-12945

Published: 27/11/2019 Updated: 04/12/2019
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Insufficient validation of user-supplied input for the Solstice Pod prior to 2.8.4 networking configuration enables authenticated malicious users to execute arbitrary commands as root.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mersive solstice_firmware

Exploits

Mersive Solstice version 280 suffers from a remote code execution vulnerability ...

Github Repositories

Exploit for CVE-2017-12945.

CVE-2017-12945 Exploit for CVE-2017-12945 A (remote) (authenticated) (blind) OS command injection vulnerability exists in Mersive Solstice Pods - a wireless collaboration and presentation platform designed by Mersive Technologies Inc - running versions of the firmware prior to 284, as acknowledged/reported on the vendor website, see the screenshot below As a result, an auth