CVE-2019-11527: OS Command Injection
Published Oct 10, 2019
·Updated
An issue was discovered in Softing uaGate SI 1.60.01. A CGI script is vulnerable to command injection with a maliciously crafted url parameter.
Affected Software
2 affected components
Softing Uagate Si Firmware=1.60.01
Softing uaGate SI
Event History
Oct 10, 2019
CVE Published
via MITRE·07:37 PM
Data Sourced
via MITRE·07:37 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-11527.
2
What is the severity of CVE-2019-11527?
The severity of CVE-2019-11527 is critical with a severity value of 8.8.
3
What is affected by CVE-2019-11527?
Softing uaGate SI firmware version 1.60.01 is affected by CVE-2019-11527.
4
How can an attacker exploit CVE-2019-11527?
An attacker can exploit CVE-2019-11527 by injecting malicious commands through a crafted URL parameter in a CGI script.
5
Is Softing uaGate SI vulnerable to CVE-2019-11527?
No, Softing uaGate SI is not vulnerable to CVE-2019-11527.