7.5
CVSSv3

CVE-2020-14293

Published: 02/10/2020 Updated: 09/10/2020
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 756
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

conf_datetime in Secudos DOMOS 5.8 allows remote malicious users to execute arbitrary commands as root via shell metacharacters in the zone field (obtained from the web interface).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

secudos domos

Exploits

DOMOS versions 58 and below suffer from a command injection vulnerability ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> [SYSS-2020-025] DOMOS 58 - OS Command Injection <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Patrick ...

Github Repositories

This repository holds the advisory, exploits and vulnerable software of the CVE-2020-14293

CVE-2020-14293 This vulnerablity was discovered and disclosed by me This repository will hold the advisory, vulnerable software and the exploits This repository is only for educational purposes Links Advisory SYSS-2020-025 Detailed writeup SySS Blog entry [Exploit on Exploit-DB](wwwexploit-dbcom/exploits/xxxxx - TODO) Vendor notice MITRE Entry NVD Entry Software