CVE-2019-12585: OS Command Injection
Published Jun 3, 2019
·Updated
Apcupsd 0.3.915, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsdstatus.php.
Affected Software
6 affected components
Apcupsd Apcupsd=0.3.91_5
Netgate pfSense<2.4.4
Netgate pfSense=2.4.4
Netgate pfSense=2.4.4-p1
Netgate pfSense=2.4.4-p2
Netgate pfSense=2.4.4-p3
Remediation
Event History
Jun 3, 2019
CVE Published
via MITRE·02:28 AM
Data Sourced
via MITRE·02:28 AM
Description
Frequently Asked Questions
1
What is CVE-2019-12585?
CVE-2019-12585 is an Arbitrary Command Execution vulnerability in Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products.
2
How severe is CVE-2019-12585?
CVE-2019-12585 has a severity rating of 9.8 (Critical).
3
How does CVE-2019-12585 affect pfSense?
CVE-2019-12585 affects pfSense versions up to 2.4.4-RELEASE-p3.
4
How can I fix CVE-2019-12585?
To fix CVE-2019-12585, update Apcupsd to a version higher than 0.3.91_5 and upgrade pfSense to a version higher than 2.4.4-RELEASE-p3.
5
Where can I find more information about CVE-2019-12585?
More information about CVE-2019-12585 can be found at the following references: [Link1], [Link2], [Link3].