First published: Fri Jul 21 2017(Updated: )
In Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, the "PING" (aka tag_ipPing) feature within the web interface allows performing command injection, via the "pip" parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Greenpacket Dx-350 | =2.8.9.5-g1.4.8-atheeb | |
Greenpacket Dx-350 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9980 has a high severity rating due to its ability to allow command injection through a web interface.
To fix CVE-2017-9980, upgrade the Green Packet DX-350 Firmware to a version that is not affected by this vulnerability.
CVE-2017-9980 affects Green Packet DX-350 Firmware version 2.8.9.5-g1.4.8-atheeb.
The impact of CVE-2017-9980 includes potential unauthorized command execution on the affected device.
CVE-2017-9980 exploits the web interface by using the 'pip' parameter in the PING feature to perform command injection.