9
CVSSv2

CVE-2018-10123

Published: 16/05/2018 Updated: 03/10/2019
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 905
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

p910nd on Inteno IOPSYS 2.0 up to and including 4.2.0 allows remote malicious users to read, or append data to, arbitrary files via requests on TCP port 9100.

Vulnerable Product Search on Vulmon Subscribe to Product

intenogroup iopsys_firmware

Exploits

''' Any authenticated user can modify the configuration for it in a way which allows them to read and append to any file as root This leads to information disclosure and remote code execution This vulnerability has been assigned the CVE ID: CVE-2018-10123 This PoC requires Python 36 and a module called websocket-client which you can install by ...
Inteno IOPSYS version 20 - 420 p910nd suffers from a remote command execution vulnerability ...