CVE-2017-9980: Command Injection
Published Jul 21, 2017
·Updated
In Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, the "PING" (aka tagipPing) feature within the web interface allows performing command injection, via the "pip" parameter.
Affected Software
2 affected components
GreenPacket Dx-350 Firmware=2.8.9.5-g1.4.8-atheeb
GreenPacket Dx-350
Event History
Jul 21, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9980?
CVE-2017-9980 has a high severity rating due to its ability to allow command injection through a web interface.
2
How do I fix CVE-2017-9980?
To fix CVE-2017-9980, upgrade the Green Packet DX-350 Firmware to a version that is not affected by this vulnerability.
3
What systems are affected by CVE-2017-9980?
CVE-2017-9980 affects Green Packet DX-350 Firmware version 2.8.9.5-g1.4.8-atheeb.
4
What is the impact of CVE-2017-9980 on my system?
The impact of CVE-2017-9980 includes potential unauthorized command execution on the affected device.
5
How does CVE-2017-9980 exploit the web interface?
CVE-2017-9980 exploits the web interface by using the 'pip' parameter in the PING feature to perform command injection.