CVE-2017-7175: OS Command Injection
Published Jul 10, 2017
·Updated
NfSen before 1.3.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the customfmt parameter (aka the "Custom output format" field).
Affected Software
1 affected component
NfSen NfSen<=1.3.7
Event History
Jul 10, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-7175?
CVE-2017-7175 is classified as a high severity vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2017-7175?
To fix CVE-2017-7175, upgrade NfSen to version 1.3.8 or later.
3
What systems are affected by CVE-2017-7175?
CVE-2017-7175 affects NfSen versions prior to 1.3.8.
4
Can CVE-2017-7175 be exploited remotely?
Yes, CVE-2017-7175 can be exploited by remote attackers through crafted input in the customfmt parameter.
5
What is the impact of CVE-2017-7175 on affected systems?
The impact of CVE-2017-7175 can lead to arbitrary OS command execution on the affected NfSen systems.