ID |
CVE-2022-32268
|
Sažetak |
StarWind SAN and NAS v0.2 build 1914 allow remote code execution. A flaw was found in REST API in StarWind Stack. REST command, which allows changing the hostname, doesn’t check a new hostname parameter. It goes directly to bash as part of a script. An attacker with non-root user access can inject arbitrary data into the command that will be executed with root privileges. |
Reference |
|
CVSS |
Base: | 9.0 |
Impact: | 10.0 |
Exploitability: | 8.0 |
|
Pristup |
Vektor | Složenost | Autentikacija |
NETWORK |
LOW |
SINGLE |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
COMPLETE |
COMPLETE |
COMPLETE |
|
CVSS vektor |
AV:N/AC:L/Au:S/C:C/I:C/A:C |
Zadnje važnije ažuriranje |
16-11-2022 - 16:56 |
Objavljeno |
03-06-2022 - 06:15 |