First published: Mon Nov 15 2010(Updated: )
gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the DRIVES parameter, as demonstrated by a cross-site request forgery (CSRF) attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti LANDESK Management Suite | =4.0-1.48 | |
Ivanti LANDESK Management Suite | =4.2 | |
Ivanti LANDESK Management Suite | =4.0 | |
Ivanti LANDESK Management Suite | =4.2-1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2892 is considered a high severity vulnerability due to the potential for remote command execution.
To fix CVE-2010-2892, upgrade to a version of LANDesk Management Gateway that is not affected by this vulnerability.
CVE-2010-2892 affects LANDesk Management Gateway versions 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8.
Yes, CVE-2010-2892 can be exploited remotely by authenticated administrators using cross-site request forgery techniques.
CVE-2010-2892 allows attackers to execute arbitrary commands on the affected systems, which can lead to data breaches or system compromise.